NTLM Security Protocol
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 0 | NTLM Server Accept | ETW Trace | N | N |
| 1 | NTLM Client Initialize | ETW Trace | N | N |
| 2 | NTLM Validate Credentials | ETW Trace | N | N |
Event ID 0: NTLM Server Accept
#Fields #
| Name | Description |
|---|---|
StageHint mof:UInt32 | |
InContext mof:UInt32 | |
OutContext mof:UInt32 | |
Flags mof:UInt32 | |
UserName mof:String | |
DomainName mof:String | |
Workstation mof:String |
Event ID 1: NTLM Client Initialize
#Provenance
ETW provider GUID {C92CF544-91B3-4DC0-8E11-C580339A0BF8}
- WS2025-26100.0, schema read from the WMI MOF class, captured 2026-02-26
Taken from Windows installation media (build 26100.1), not a patched system, so the exact update level is unknown.
- WS2022-20348.4893, schema read from the WMI MOF class, captured 2026-06-02
MOF class: MSV1_0Trace
- Win11-26200.6584, schema read from the WMI MOF class, captured 2026-06-02
MOF class: MSV1_0Trace