cscli scenarios install a1ad/mikrotik-bf
Detect failed Mikrotik authentications:
1# Mikrotik BF scan2name: a1ad/mikrotik-bf3description: "Detect Mikrotik bruteforce"4filter: "evt.Meta.log_type == 'mikrotik_failed_auth'"5#debug: true6type: leaky7groupby: evt.Meta.source_ip8leakspeed: "20s"9capacity: 510blackhole: 1m11labels:12 service: mikrotik13 behavior: "iot:bruteforce"14 classification:15 - attack.T111016 spoofable: 017 confidence: 318 label: "Mikrotik Bruteforce"19 remediation: true20---21# meshcentral user-enum22type: leaky23name: a1ad/mikrotik-bf_user-enum24description: "Detect mikrotik user enum bruteforce"25filter: "evt.Meta.log_type == 'mikrotik_failed_auth'"26groupby: evt.Meta.source_ip27distinct: evt.Meta.user28leakspeed: 10s29capacity: 530blackhole: 1m31labels:32 service: mikrotik33 behavior: "iot:bruteforce"34 classification:35 - attack.T158936 - attack.T111037 spoofable: 038 confidence: 339 label: "Mikrotik User Enumeration"40 remediation: true41