cscli scenarios install aidalinfo/tcpudp-flood-traefik
1type: leaky2name: aidalinfo/tcpudp-flood-traefik3description: "Detect TCP/UDP flood"4filter: "evt.Meta.log_type == 'traefik_tcpudp'"5groupby: "evt.Meta.source_ip"6capacity: 10007cache_size: 108leakspeed: "10s"9blackhole: 5m10labels:11 remediation: true12 classification:13 - attack.T149814 spoofable: 015 confidence: 216 label: "UDP or TCP Flood Traefik"17