Skip to content
#

eventlog-analysis

Here are 3 public repositories matching this topic...

Language: All
Filter by language

PowerShell script to audit NTLM authentication events from Windows Security and NTLM Operational logs. Filters by NTLMv1/v2, failed logons, privileged sessions (4672), date ranges, and null sessions. Validates NTLM audit GPO settings. Targets localhost, remote servers, domain controllers, or an entire AD forest.

  • Updated Mar 4, 2026
  • PowerShell

Improve this page

Add a description, image, and links to the eventlog-analysis topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the eventlog-analysis topic, visit your repo's landing page and select "manage topics."

Learn more