Detects logons using NTLM, which could be caused by a legacy source or attackers
condition: selection selection: EventID: 8002