๐ Secure Bits ๐ก
๐๐ฒ๐๐๐ถ๐ป๐ด ๐ฟ๐ถ๐ฑ ๐ผ๐ณ ๐ก๐ง๐๐ ๐ถ๐ ๐ณ๐ถ๐ป๐ฎ๐น๐น๐ ๐ฒ๐ฎ๐๐ถ๐ฒ๐ฟ (๐ฎ๐ป๐ฑ ๐๐บ๐ฎ๐ฟ๐๐ฒ๐ฟ)
In Windows 11 version 24H2 and Windows Server 2025, Microsoft introduced ๐ฒ๐ป๐ต๐ฎ๐ป๐ฐ๐ฒ๐ฑ ๐ก๐ง๐๐ ๐น๐ผ๐ด๐ด๐ถ๐ป๐ด โ and itโs a game changer for organizations trying to decommission NTLM.
Letโs break it down ๐
โธป
๐ข๐๐ ๐ช๐๐ฌ
๐ ย ๐๐ฃ๐ข:
โข ๐๐ฆ๐ค๐ถ๐ณ๐ช๐ต๐บ ๐๐ฆ๐ต๐ต๐ช๐ฏ๐จ๐ด > ๐๐ฅ๐ท๐ข๐ฏ๐ค๐ฆ๐ฅ ๐๐ถ๐ฅ๐ช๐ต ๐๐ฐ๐ญ๐ช๐ค๐บ ๐๐ฐ๐ฏ๐ง๐ช๐จ๐ถ๐ณ๐ข๐ต๐ช๐ฐ๐ฏ > ๐๐ค๐ค๐ฐ๐ถ๐ฏ๐ต ๐๐ฐ๐จ๐ฐ๐ฏ > ๐๐ถ๐ฅ๐ช๐ต ๐๐ณ๐ฆ๐ฅ๐ฆ๐ฏ๐ต๐ช๐ข๐ญ ๐๐ข๐ญ๐ช๐ฅ๐ข๐ต๐ช๐ฐ๐ฏ
โข ๐๐ฆ๐ค๐ถ๐ณ๐ช๐ต๐บ ๐๐ฆ๐ต๐ต๐ช๐ฏ๐จ๐ด > ๐๐ฅ๐ท๐ข๐ฏ๐ค๐ฆ๐ฅ ๐๐ถ๐ฅ๐ช๐ต ๐๐ฐ๐ญ๐ช๐ค๐บ ๐๐ฐ๐ฏ๐ง๐ช๐จ๐ถ๐ณ๐ข๐ต๐ช๐ฐ๐ฏ > ๐๐ฐ๐จ๐ฐ๐ฏ/๐๐ฐ๐จ๐ฐ๐ง๐ง > ๐๐ถ๐ฅ๐ช๐ต ๐๐ฐ๐จ๐ฐ๐ฏ
๐ย ๐๐๐ฒ๐ป๐๐:
โข 4776 โ NTLM usage (no version, no reason, no process)
โข 4624 โ NTLM ๐๐ฒ๐ฟ๐๐ถ๐ผ๐ป shown – must be collected on the client side
โ It was hard to get a global view of NTLM usage and the context behind it.
โธป
“๐ก๐๐ช๐๐ฅ” ๐ช๐๐ฌ
๐ ย ๐๐ฃ๐ข:
โข ๐๐ฐ๐ค๐ข๐ญ ๐๐ฐ๐ญ๐ช๐ค๐ช๐ฆ๐ด > ๐๐ฆ๐ค๐ถ๐ณ๐ช๐ต๐บ ๐๐ฑ๐ต๐ช๐ฐ๐ฏ๐ด > ๐๐ฆ๐ต๐ธ๐ฐ๐ณ๐ฌ ๐ด๐ฆ๐ค๐ถ๐ณ๐ช๐ต๐บ: ๐๐ฆ๐ด๐ต๐ณ๐ช๐ค๐ต ๐๐๐๐: ๐๐ถ๐ฅ๐ช๐ตโฆ
๐ย ๐๐๐ฒ๐ป๐๐:
โข 8001 โ Client: outgoing NTLMย blocked; showsย ๐ฝ๐ฟ๐ผ๐ฐ๐ฒ๐๐;ย no version
โข 8002 โ Target device: incoming NTLM blocked
โข 8003 โ Service host: NTLM blocked; shows process; no version
โข 8004โ8006 โ NTLM authentication blocks on DC
โ ๏ธ These events show which process initiated the NTLM authentication (plus details) and whether it would be/was blocked. But we still lack a DC-side log that captures the full NTLM transaction.
โธป
๐ก๐๐ช
๐ ย ๐๐ฃ๐ข:
โข ๐๐ฅ๐ฎ๐ช๐ฏ๐ช๐ด๐ต๐ณ๐ข๐ต๐ช๐ท๐ฆ ๐๐ฆ๐ฎ๐ฑ๐ญ๐ข๐ต๐ฆ๐ด > ๐๐บ๐ด๐ต๐ฆ๐ฎ > ๐๐๐๐ > ๐๐๐๐ ๐๐ฏ๐ฉ๐ข๐ฏ๐ค๐ฆ๐ฅ ๐๐ฐ๐จ๐จ๐ช๐ฏ๐จ
โข ๐๐ฅ๐ฎ๐ช๐ฏ๐ช๐ด๐ต๐ณ๐ข๐ต๐ช๐ท๐ฆ ๐๐ฆ๐ฎ๐ฑ๐ญ๐ข๐ต๐ฆ๐ด > ๐๐บ๐ด๐ต๐ฆ๐ฎ > ๐๐ฆ๐ต๐ญ๐ฐ๐จ๐ฐ๐ฏ > ๐๐ฐ๐จ ๐๐ฏ๐ฉ๐ข๐ฏ๐ค๐ฆ๐ฅ ๐๐ฐ๐ฎ๐ข๐ช๐ฏ-๐ธ๐ช๐ฅ๐ฆ ๐๐๐๐ ๐๐ฐ๐จ๐ด
๐ย ๐๐๐ฒ๐ป๐๐:
โข 4020/4021 โ Client-side: NTLM version, ๐ฝ๐ฟ๐ผ๐ฐ๐ฒ๐๐, and ๐ฟ๐ฒ๐ฎ๐๐ผ๐ป
โข 4022/4023 โ Server-side: NTLM version and local process
โข 4030/4031 โ DC-side: NTLM version, service, cross-domain
โข 4032/4033 โ DC-side: NTLM ๐๐ฒ๐ฟ๐๐ถ๐ผ๐ป, service, same-domain
๐ฏ On the client, youโll seeย whyย NTLM fired, but theย ๐ฑ๐ผ๐บ๐ฎ๐ถ๐ป ๐ฐ๐ผ๐ป๐๐ฟ๐ผ๐น๐น๐ฒ๐ฟ ๐ด๐ถ๐๐ฒ๐ ๐๐ผ๐ ๐๐ต๐ฒ ๐ฑ๐ฒ๐๐ฎ๐ถ๐น๐ ๐๐ผ๐ ๐ฎ๐ฐ๐๐๐ฎ๐น๐น๐ ๐ป๐ฒ๐ฒ๐ฑ (NTLM version, SPN, etc.). Start your review on the DC to map where NTLM is used, then drill down into specific clients/servers as needed.
โธป
โ๐ฆ๐๐ถ๐น๐น ๐ฟ๐ฒ๐น๐๐ถ๐ป๐ด ๐ผ๐ป ๐ก๐ง๐๐ in your environment?
