cscli scenarios install MariuszKociubinski/bitwarden-bfDetect failed bitwarden authentications:
1# bitwarden BF scan2name: MariuszKociubinski/bitwarden-bf3description: "Detect bitwarden bruteforce"4filter: "evt.Meta.log_type == 'bitwarden_failed_auth'"5#debug: false6type: leaky7groupby: evt.Meta.source_ip8leakspeed: 20s9capacity: 510blackhole: 1m11labels:12 service: bitwarden13 behavior: "http:bruteforce"14 spoofable: 015 confidence: 316 classification:17 - attack.T111018 label: "Bitwarden Bruteforce"19 remediation: true20