cscli scenarios install LePresidente/redmine-bf
Detect failed Redmine authentications:
1# Redmine bruteforce2type: leaky3name: LePresidente/redmine-bf4description: "Detect Redmine bruteforce attacks"5filter: "evt.Meta.log_type == 'redmine_failed_auth'"6leakspeed: 1m7capacity: 58groupby: evt.Meta.source_ip9blackhole: 5m10reprocess: true11labels:12 service: redmine13 behavior: "http:bruteforce"14 classification:15 - attack.T111016 label: "Redmine Bruteforce"17 spoofable: 018 confidence: 319 remediation: true20---21# Redmine user-enum22type: leaky23name: LePresidente/redmine-bf_user-enum24description: "Detect Redmine user enum bruteforce"25filter: "evt.Meta.log_type == 'redmine_failed_auth'"26groupby: evt.Meta.source_ip27distinct: evt.Meta.user28leakspeed: 10s29capacity: 530blackhole: 1m31labels:32 service: redmine33 behavior: "http:bruteforce"34 spoofable: 035 confidence: 336 classification:37 - attack.T158938 - attack.T111039 label: "Redmine Enumeration"40 remediation: true41