Detect NTLM
NTLM is an authentication method commonly used by Windows servers
Detection looks at response headers across 1 fingerprint rules among the site's public responses.
01
Websites using NTLM
Loading website list…
02
Signal classes
PluginView evaluates public page signals in these classes when identifying NTLM. Individual fingerprint rule bodies are proprietary and are not published.
- Response headers
03
Example public indicators for NTLM
Illustrative indicators derived from public catalog metadata for NTLM. A live scan may match additional proprietary rules beyond these examples.
- www-authenticate: NTLM
04
What a detection means
- Establishes
- One or more public signals on the scanned page matched a known NTLM signature (1 rules) at the time of the scan.
- Does not establish
- A sitewide install of NTLM, an active vendor contract, exclusive use, or that NTLM is still in place today.
05
How to check a site for NTLM
- 1. Enter the website URL in the scan form — homepage, pricing, checkout, or login pages usually expose the strongest NTLM signals.
- 2. PluginView reads only public responses (response headers) and scores them against the NTLM signature set (1 rules).
- 3. Review the confidence score and text explanation for NTLM on the results page.
06
FAQ: detecting NTLM
- Can PluginView detect NTLM without logging in?
- Yes. PluginView only reads publicly accessible responses when checking for NTLM — typically response headers. It does not bypass authentication or paywalls.
- What category is NTLM?
- NTLM is classified under Security in the PluginView directory.
- How many fingerprint rules cover NTLM?
- This reference currently tracks 1 fingerprint rule across response headers. Individual rule bodies are proprietary and are not published.
- What public signals suggest a site uses NTLM?
- Illustrative public indicators for NTLM include www-authenticate: NTLM. A live scan may match additional proprietary rules beyond these examples.