Update win_admin_rdp_login.yml

Getting rid of '*' use
This commit is contained in:
Jonhnathan 2020-10-15 15:02:40 -03:00 committed by GitHub
parent 9c7a23e432
commit 085dc21d25
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -23,7 +23,7 @@ detection:
EventID: 4624
LogonType: 10
AuthenticationPackageName: Negotiate
AccountName: 'Admin-*'
AccountName|startswith: 'Admin-'
condition: selection
falsepositives:
- Legitimate administrative activity