Pass-the-Hash Lateral Movement via NTLM Network Logon + Admin Share
This rule detects potential Pass-the-Hash lateral movement by identifying NTLM network logons (Event ID 4624, LogonType 3) on a host that lack a preceding interactive (LogonType 2, 10) or Kerberos-authenticated logon, coupled with subsequent access to sensitive administrative shares (Event ID 5140) by the same user account.
Microsoft Sentinel (KQL)

