This is an automated archive.
The original was posted on /r/cybersecurity by /u/kennnethreid on 2023-08-29 16:14:32+00:00.
Hi All,
I’ve been reading into password spraying attacks and how they work, but I have a question I’m hoping someone can help or point me in the right direction.
Naturally NTLM password spraying attacks don’t display any source IP Address due to the authentication protocol it is using, if this is the case how can I utilise SIEM to find the source of this attack? Is it possible?
You must log in or # to comment.