cscli scenarios install LearningSpot/dockge-bf
Detect failed authentications for Dockge:
leakspeed of 1m, capacity of 5, blackhole of 5m on source ip and user enumeration
1# Dockge Bruteforce2type: leaky3name: LearningSpot/dockge-bf4description: "Detect Dockge Bruteforce"5filter: evt.Meta.log_type == 'dockge_failed_auth'6groupby: evt.Meta.source_ip7leakspeed: 1m8capacity: 59blackhole: 5m10labels:11 service: dockge12 classification:13 - attack.T111014 behavior: "http:bruteforce"15 confidence: 316 spoofable: 017 label: "Dockge Bruteforce"18 remediation: true19---20# Dockge User Enumeration21type: leaky22name: LearningSpot/dockge_bf_user_enum23description: "Detect Dockge User Enumeration Bruteforce"24filter: evt.Meta.log_type == 'dockge_failed_auth'25distinct: evt.Meta.username26groupby: evt.Meta.source_ip27leakspeed: 1m28capacity: 529blackhole: 5m30labels:31 service: dockge32 classification:33 - attack.T158934 - attack.T111035 behavior: "http:bruteforce"36 confidence: 337 spoofable: 038 label: "Dockge User Enumeration"39 remediation: true40