Skip to content
NTLM

NTLM Event ID 8001: Outgoing authentication audit

NTLM client blocked audit: Audit outgoing NTLM authentication traffic that would be blockedNTLM event 8001 logs outgoing NTLM authentication from this computer: target server, supplied user and client process. Shows which apps still use NTLM.
8001
Event ID
8001
Channel
Microsoft-Windows-NTLM/Operational
Provider
Microsoft-Windows-NTLM
Log file
Microsoft-Windows-NTLM%4Operational.evtx
Category
NTLM
Default logging
Needs configuration

What event 8001 means

Event 8001 is written on the client when it sends NTLM authentication to a remote server and outgoing NTLM auditing is enabled. It is an audit record: it describes traffic that would be blocked if outgoing NTLM were restricted, but nothing is actually blocked.

The event answers what the server-side logs cannot: which process used NTLM (ProcessName, CallerPID), under which local identity (ClientUserName, ClientDomainName, ClientLUID), which credentials were supplied (UserName, DomainName) and which target was contacted (TargetName, usually an SPN-like string such as cifs/10.0.0.5 or HTTP/server).

A target given as an IP address, or PID 4 with an empty process name (SMB traffic from the kernel redirector), are the most common patterns. For threat hunting, NTLM sent to unexpected or external targets can reveal coerced or forced authentication.

When it is logged

Audit policy / configuration

Security Options > Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers = Audit all. Events go to Applications and Services Logs > Microsoft > Windows > NTLM > Operational.

Available since Windows 7 / Server 2008 R2. For SMB, the caller is the kernel redirector, so CallerPID is 4 and ProcessName is empty; use other telemetry to find the real application.

Key fields

FieldWhat it tells you
TargetNameTarget the credentials were sent to, e.g. cifs/fileserver, cifs/10.0.0.5, HTTP/10.0.0.8. An IP address here explains why Kerberos was not used.
UserNameUser name explicitly supplied for the authentication, or (NULL) when the current logon credentials were used.
DomainNameDomain explicitly supplied, or (NULL).
CallerPIDPID of the process that requested the authentication; 4 for kernel-mode SMB.
ProcessNamePath of the calling process, e.g. a browser, svchost.exe or a custom tool.
ClientLUIDLogon session (LUID) of the calling process; match it with 4624 TargetLogonId.
ClientUserNameAccount the calling process runs as.
ClientDomainNameDomain of the account the calling process runs as.
MechanismOIDNegotiation mechanism OID, often (NULL).

Common benign sources

  • Drives mapped or resources accessed by IP address instead of host name.
  • Legacy applications and appliances that only support NTLM.
  • Services connecting to servers without a correct SPN, falling back from Kerberos to NTLM.

What attackers do that produces it

  • Forced or coerced authentication (malicious UNC paths in documents or shortcuts, WebDAV) making the host send NTLM to an attacker-controlled or external address.
  • Tools using alternate credentials over NTLM for lateral movement, visible as a supplied UserName different from ClientUserName.

Investigation tips

  • Group by TargetName and ProcessName to build an inventory of NTLM consumers; review targets outside the internal address space first.
  • Compare UserName with ClientUserName — explicitly supplied credentials from an unusual process deserve attention.
  • Match with 8003 on the target server and 8004 on the domain controller for the full chain.
  • For PID 4 (SMB), look at process and network telemetry (Sysmon 3, 5156) at the same time to find the originating program.

MITRE ATT&CK techniques

TechniqueTactics
T1187 Forced AuthenticationCredential Access
T1550.002 Use Alternate Authentication Material: Pass the HashLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading