diff --git a/rules/windows/builtin/security/win_security_successful_external_remote_smb_login.yml b/rules/windows/builtin/security/win_security_successful_external_remote_smb_login.yml index f9d424e5c..4f1324f66 100644 --- a/rules/windows/builtin/security/win_security_successful_external_remote_smb_login.yml +++ b/rules/windows/builtin/security/win_security_successful_external_remote_smb_login.yml @@ -34,8 +34,8 @@ detection: - IpAddress: '::1' # IPv6 loopback - IpAddress|startswith: - 'fe80:' # link-local address - - 'fc00:' # private address range fc00::/7 - - 'fd00:' # private address range fd00::/8 + - 'fc' # private address range fc00::/7 + - 'fd' # private address range fc00::/7 filter_empty: IpAddress: '-' condition: selection and not 1 of filter_*