Pass-the-Hash via NTLM Network Logon from Non-Domain Source Account
Detects potential Pass-the-Hash (PtH) activity by identifying NTLM Type 3 logons where the account domain originates from outside the local or known corporate domain. The rule specifically excludes system-related accounts such as ANONYMOUS LOGON, WORKGROUP, and NT AUTHORITY, focusing on attempts to authenticate against internal resources using potentially forged or captured credentials.
Microsoft Sentinel (KQL)

