
Threat Intelligence
Stop Pass-the-Hash Attacks: Practical Prevention and Detection
Disabling NTLM alone fails because modern protocols like Kerberos and SMB can still carry credential material, requiring layered identity controls.
Everything Payload Report has reported about identity security: 2 stories, newest first. Part of our Threat Intelligence coverage.

Disabling NTLM alone fails because modern protocols like Kerberos and SMB can still carry credential material, requiring layered identity controls.

Login alerts provide a false sense of security by reporting events after the damage is often done, requiring specific configuration to be useful.