Pass-the-Hash Detection (NTLM Logon Type 3)
This rule detects potential Pass-the-Hash (PtH) attacks by looking for multiple successful network logons (LogonType 3) using NTLM authentication for the same user from the same IP address. A count of 5 or more such events is considered suspicious.
Microsoft Sentinel (KQL)

