alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg: "[PALO-ALTO] NTLM Authentication Brute Force - [25/1]"; content: "NTLM authentication failed for user"; after: track by_src, count 15, seconds 300; threshold: type limit, track by_src, count 1, seconds 86400; flowbits: set,brute_force,21600; parse_src_ip: 1; classtype: unsuccessful-user; reference: url,; sid: 5002588; rev: 2;)

