diff --git a/rules/windows/builtin/win_susp_ntlm_rdp.yml b/rules/windows/builtin/win_susp_ntlm_rdp.yml index bed9e568a..96e1d00a8 100644 --- a/rules/windows/builtin/win_susp_ntlm_rdp.yml +++ b/rules/windows/builtin/win_susp_ntlm_rdp.yml @@ -16,7 +16,7 @@ logsource: detection: selection: EventID: 8001 - TargetName: TERMSRV* + TargetName|startswith: TERMSRV condition: selection fields: - Computer