Get-NtlmLogonEvents
5.3.0-preview0001
PowerShell module to audit NTLM authentication events from Windows Security and NTLM Operational logs. Filters by NTLMv1/v2, failed logons, privileged sessions (4672), date ranges, and null sessions. Validates NTLM audit GPO settings. Targets localhost, remote servers, domain controllers, or an entire AD forest.
Minimum PowerShell version
5.0
This is a prerelease version of Get-NtlmLogonEvents.
Installation Options
Owners
Copyright
(c) Jan Tiedemann. All rights reserved.
Package Details
Author(s)
- Jan Tiedemann
Tags
NTLM Security EventLog Authentication Audit ActiveDirectory
Functions
Dependencies
This module has no dependencies.
FileList
- Get-NtlmLogonEvents.nuspec
- Get-NtlmLogonEvents.psd1
- Get-NtlmLogonEvents.psm1
- en-US\about_Get-NtlmLogonEvents.help.txt
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 5.3.0-previe... (current version) | 2 | 4/1/2026 |
| 5.2.0 | 2 | 4/1/2026 |
| 5.1.0 | 2 | 4/1/2026 |
| 1.0.0 | 2 | 4/1/2026 |
| 0.2.0-previe... | 3 | 4/1/2026 |