Robuta

https://www.elastic.co/docs/reference/security/prebuilt-rules/rules/windows/defense_evasion_ntlm_downgrade Potential NetNTLMv1 Downgrade Attack | Prebuilt detection rules reference Identifies registry modification to force the system to fall back to NTLMv1 for authentication. This modification is possible with local administrator... detection rulespotentialdowngradeattackprebuilt