cscli scenarios install PintjesB/technitium-bfScenario to trigger when a certain IP has too many failed auths.
1# Technitium bruteforce2type: leaky3name: PintjesB/technitium-bf4description: "Detect Technitium bruteforce attacks"5filter: "evt.Meta.log_type == 'technitium_failed_auth'"6leakspeed: 1m7capacity: 58groupby: evt.Meta.source_ip9blackhole: 5m10reprocess: true11labels:12 service: technitium13 spoofable: 014 confidence: 315 classification:16 - attack.T111017 label: "Technitium bruteforce"18 behavior: "http:bruteforce"19 remediation: true20