cscli scenarios install Dominic-Wagner/vaultwarden-bf
Detect failed vaultwarden authentications:
1# vaultwarden bruteforce2type: leaky3name: Dominic-Wagner/vaultwarden-bf4description: "Detect vaultwarden bruteforce"5filter: "evt.Meta.log_type in ['vaultwarden_failed_auth', 'vaultwarden_failed_admin_auth', 'vaultwarden_failed_2fa_totp', 'vaultwarden_failed_2fa_email']"6leakspeed: 1m7capacity: 58groupby: evt.Meta.source_ip9blackhole: 5m10reprocess: true11labels:12 service: vaultwarden13 behavior: "generic:bruteforce"14 classification:15 - attack.T111016 label: "Vaultwarden Bruteforce"17 spoofable: 018 confidence: 319 remediation: true20---21# vaultwarden user-enum22type: leaky23name: Dominic-Wagner/vaultwarden-bf_user-enum24description: "Detect vaultwarden user enum bruteforce"25filter: evt.Meta.log_type == 'vaultwarden_failed_auth'26groupby: evt.Meta.source_ip27distinct: evt.Meta.username28leakspeed: 1m29capacity: 530blackhole: 5m31reprocess: true32labels:33 service: vaultwarden34 behavior: "generic:bruteforce"35 classification:36 - attack.T158937 - attack.T111038 label: "Vaultwarden User Enumeration"39 spoofable: 040 confidence: 341 remediation: true42