cscli scenarios install Jgigantino31/calibre-web-bfDetect failed calibre-web authentications:
1# calibre-web BF scan2name: Jgigantino31/calibre-web-bf3description: "Detect calibre-web bruteforce"4filter: "evt.Meta.log_type == 'calibre-web_failed_auth'"5#debug: true6type: leaky7groupby: evt.Meta.source_ip8leakspeed: 20s9capacity: 510blackhole: 1m11labels:12 service: calibre-web13 behavior: "http:bruteforce"14 spoofable: 015 confidence: 316 classification:17 - attack.T111018 label: "Calibre-Web Bruteforce"19 remediation: true20---21# calibre-web user-enum22type: leaky23name: Jgigantino31/calibre-web-bf_user-enum24description: "Detect calibre-web user enum bruteforce"25filter: "evt.Meta.log_type == 'calibre-web_failed_auth'"26groupby: evt.Meta.source_ip27distinct: evt.Meta.user28leakspeed: 1m29capacity: 530blackhole: 1m31labels:32 service: calibre-web33 behavior: "http:bruteforce"34 spoofable: 035 confidence: 336 classification:37 - attack.T158938 - attack.T111039 label: "Calibre-Web User Enumeration"40 remediation: true41