Rapid Lateral Movement via NTLM Authentication
This rule detects potential lateral movement by monitoring successful network logons using NTLM authentication across multiple distinct destination hosts within a short time window. It calculates the frequency of connections to unique hosts to identify anomalous, rapid traversal through a network by a single user account, excluding known system accounts.
Microsoft Sentinel (KQL)

