Typical severity: High. Likelihood of attack: Medium. An adversary obtains (i.e. steals or purchases) legitimate Windows domain credential hash values to access systems within the domain that leverage the Lan Man (LM) and/or NT Lan Man (NTLM) authentication protocols.
Prevent the use of Lan Man and NT Lan Man authentication on severs and apply patch KB2871997 to Windows 7 and higher systems. | Leverage multi-factor authentication for all authentication services and prior to granting an entity access to the domain network. | Monitor system and domain logs for abnormal credential access. | Create a strong password policy and ensure that your system enforces this policy. | Leverage system penetration testing and other defense in depth methods to determine vulnerable systems within a domain.