RDP Brute-Force Multiple NLA Negotiation Attempts from Single Source
This rule detects multiple Network Level Authentication (NLA) negotiation attempts targeting port 3389 from a single source within a 60-second window, which is indicative of an RDP brute-force attack.
Suricata

