From fa472be0fd30ed6f9ca5df56adde7b3b482541fc Mon Sep 17 00:00:00 2001 From: Yamato Security <71482215+YamatoSecurity@users.noreply.github.com> Date: Sat, 18 Mar 2023 04:31:25 +0900 Subject: [PATCH] Update rules/windows/builtin/security/win_security_successful_external_remote_smb_login.yml Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com> --- .../win_security_successful_external_remote_smb_login.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/rules/windows/builtin/security/win_security_successful_external_remote_smb_login.yml b/rules/windows/builtin/security/win_security_successful_external_remote_smb_login.yml index f9d424e5c..4f1324f66 100644 --- a/rules/windows/builtin/security/win_security_successful_external_remote_smb_login.yml +++ b/rules/windows/builtin/security/win_security_successful_external_remote_smb_login.yml @@ -34,8 +34,8 @@ detection: - IpAddress: '::1' # IPv6 loopback - IpAddress|startswith: - 'fe80:' # link-local address - - 'fc00:' # private address range fc00::/7 - - 'fd00:' # private address range fd00::/8 + - 'fc' # private address range fc00::/7 + - 'fd' # private address range fc00::/7 filter_empty: IpAddress: '-' condition: selection and not 1 of filter_*