NTLM-Analyzer
Status report · 90 days

NTLM status report

Period 27 Jun 2026 – 25 Sep 20268 agents · data since 11 Aug 2026Generated 25 Sep 2026, 22:38

27.5 % of all logons still go through NTLM.

Not enough data yet to compare with the 90 days before.
NTLM share
27.5 %
of all logons
NTLM logons
1 544
in the period
of which NTLMv1
85
insecure, switch off first
Accounts using NTLM
20
3 of them with NTLMv1
01

Trend

NTLM share per week - the goal is the zero line.

0 %10 %20 %30 %goal 0 %28.1 %last 7 daysWk 34Wk 35Wk 36Wk 37Wk 38
NTLMv1 logons per week
02

Progress

The dashboard's work list, and machines that can switch NTLM off.

4done4in progress171open
4 done in this period
Not done yet, by area
Programs (outgoing)13
Services (incoming)14
Connections (DC view)146
NTLMv1 SSO2
Each row of the dashboard's work lists is one item; whoever removes it marks it "done".

Ready to switch off

2outgoing · of 8 machines
2incoming · of 6 machines
SRV-PRINT, WKS-0107
Auditing on, watched for 30 days, no NTLM in that time: "Restrict NTLM: Deny" can be set here.
03

Risks and visibility

What needs attention first - and where the picture is incomplete.

NTLMv1act

85 NTLMv1 logons from 9 accounts, mostly svc_scan, mfp_service, t.hoffmann and 6 more. NTLMv1 can be cracked and should be switched off first.

October 2026act

12 logons use NTLMv1-derived credentials. They will break by themselves with the October 2026 change.

Failed logonsact

Possible password spraying: UNKNOWN-PC failed with 8 accounts. Find the machine and the cause.

Visibilitywatch

The picture is incomplete: 2 machines with auditing off, 135 machines use NTLM without an agent.

Relay attackswatch

108 sessions without MIC protection or channel binding - open to NTLM relay.

04

Next steps

Derived from the data, most important first.

  1. Switch off NTLMv1 for svc_scan, mfp_service, t.hoffmann and 6 more. Set LmCompatibilityLevel 5 on the machines behind it and replace or isolate devices that can only do NTLMv1.
  2. Before October 2026 move the 2 accounts with NTLMv1-derived credentials - otherwise they fail with the change.
  3. Check for password spraying: UNKNOWN-PC failed with 8 accounts.
  4. Fix service names (SPN): 4 are missing or registered wrongly, first cifs/nas01, http/intranet, cifs/archive01 and 1 more - 330 NTLM connections behind them. The setspn commands are in the dashboard.
  5. Tackle the most common cause: Target name could not be resolved by Kerberos (55×). Check the SPN: missing, wrong or duplicated (setspn -X finds duplicates).
  6. Set "Restrict NTLM: Deny" on 2 machines that have not used NTLM for 30 days: SRV-PRINT, WKS-0107.
05

What is left

The largest items by number of logons in the period.

Programs sending NTLM
Program → targetLogons
Systemin progress→ cifs/fs01.demo.nopcap.net148
svchost.exeopen→ ldap/dc01.demo.nopcap.net76
explorer.exein progress→ cifs/fs01.demo.nopcap.net65
msedge.exeopen→ HTTP/intranet62
Veeam.Backup.Service.exein progress→ cifs/nas0143
EXCEL.EXEopen→ cifs/fs01.demo.nopcap.net25
wsmprovhost.exein progress→ HOST/app0325
robocopy.exeopen→ cifs/archive0124
WINWORD.EXEopen→ cifs/fs01.demo.nopcap.net21
java.exeopen→ HTTP/erp-test19
explorer.exeopen→ nas0112
excel.exeopen→ cifs/archive011
spoolsv.exeopen→ cifs/fs011
Accounts using NTLM
AccountLogons
svc_backupfrom 32 machines to 10 servers116
t.hoffmannNTLMv1from 40 machines to 10 servers93
svc_sqlfrom 41 machines to 10 servers90
m.beckerfrom 48 machines to 10 servers87
administratorfrom 41 machines to 10 servers84
j.schulzfrom 44 machines to 10 servers85
a.kleinfrom 48 machines to 10 servers83
p.neumannfrom 42 machines to 9 servers83
d.fischerfrom 41 machines to 10 servers82
k.lorenzfrom 37 machines to 10 servers78
s.wagnerfrom 35 machines to 10 servers75
svc_monitorfrom 20 machines to 10 servers75
svc_webfrom 34 machines to 9 servers72
svc_scanNTLMv1from 4 machines to 3 servers40
mfp_serviceNTLMv1from 3 machines to 2 servers30
How it is counted. Based on the NTLM and logon events of the agents and domain controllers. The same logon is often seen several times - by the client, the server and the DC; it counts once. 8001 entries not confirmed by a DC do not count. The NTLM share is NTLM divided by NTLM plus Kerberos tickets. Failed logons do not count towards the share.
NTLM-Analyzer · 25 Sep 2026, 22:3890 days