cscli scenarios install andreasbrett/paperless-ngx-bf
Detect failed Paperless-ngx authentications:
1# Paperless-ngx bruteforce2type: leaky3name: andreasbrett/paperless-ngx-bf4description: "Detect Paperless-ngx bruteforce attacks"5filter: "evt.Meta.log_type == 'paperless_ngx_failed_auth'"6leakspeed: 1m7capacity: 58groupby: evt.Meta.source_ip9blackhole: 5m10reprocess: true11labels:12 service: paperless-ngx13 confidence: 314 spoofable: 015 classification:16 - attack.T111017 label: "Paperless-ngx Bruteforce"18 behavior: "http:bruteforce"19 remediation: true20---21# Paperless-ngx user-enum22type: leaky23name: andreasbrett/paperless-ngx-bf_user-enum24description: "Detect Paperless-ngx user enum bruteforce"25filter: "evt.Meta.log_type == 'paperless_ngx_failed_auth'"26groupby: evt.Meta.source_ip27distinct: evt.Meta.username28leakspeed: 1m29capacity: 530blackhole: 5m31labels:32 service: paperless-ngx33 confidence: 334 spoofable: 035 classification:36 - attack.T158937 label: "Paperless-ngx User Enumeration"38 behavior: "http:bruteforce"39 remediation: true40