Enabling ETW tracing for NTLM issues

ETW (Event Tracing for WIndows) is said to be powerful by Microsoft, but the setup of the various providers can be tedious because the documentation often lacks examples for the specific provider you desesperately need.

Here is a script to start recording NTLM authentication traces on a Domain Controller, in the existing directory of your choice

Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.