Every one carries the source it came from and the licence it was published under.
| Detection | Severity |
|---|---|
| Potential Pass-the-Hash (PtH) Attempt | Medium |
| Local Account TokenFilter Policy Disabled | Medium |
| Potential PowerShell Pass-the-Hash/Relay Script | High |
| Potential Invoke-Mimikatz PowerShell Script | Critical |
| Potential Kerberos Attack via Bifrost | High |
| NTLMv1 Logon Between Client and Server | Medium |
| Hacktool Ruler | High |
| Pass the Hash Activity 2 | Medium |
| Successful Overpass the Hash Attempt | High |
| NTLM Logon | Low |
Showing 10 of 10