cscli scenarios install andreasbrett/baikal-bf
Detect failed Baikal authentications:
1# Baikal bruteforce2type: leaky3name: andreasbrett/baikal-bf4description: "Detect Baikal bruteforce attacks"5filter: "evt.Meta.log_type in ['baikal_failed_auth', 'baikal_failed_auth_no_user']"6leakspeed: 1m7capacity: 58groupby: evt.Meta.source_ip9blackhole: 5m10reprocess: true11labels:12 service: baikal13 type: bruteforce14 classification:15 - attack.T111016 remediation: true17 behavior: http:bruteforce18 spoofable: 019 confidence: 320---21# Baikal user-enum (only for web UI since Baikal doesn't log failed username for CalDAV/CardDAV access)22type: leaky23name: andreasbrett/baikal-bf_user-enum24description: "Detect Baikal user enum bruteforce"25filter: "evt.Meta.log_type == 'baikal_failed_auth'"26groupby: evt.Meta.source_ip27distinct: evt.Meta.username28leakspeed: 1m29capacity: 530blackhole: 5m31labels:32 service: baikal33 type: bruteforce34 remediation: true35 behavior: http:bruteforce36 spoofable: 037 confidence: 338 classification:39 - attack.T1110