Windows Event Loggingand Forwarding - ACSC | Cyber.gov.au

Under ‘Powershell Scripts’, click ‘Add...’ and select the wmi_auditing.ps1. NTLM authentication The following Group Policy settings will log events for outgoing NTLM authentication, which can be vulnerable to relay and brute force attacks. ................
................