cscli scenarios install baudneo/zoneminder-bf
Bruteforce/User Enumeration protection for ZoneMinder.
1# loging bruteforce2type: leaky3name: baudneo/zoneminder-bf4description: "Detect ZoneMinder bruteforce"5filter: "evt.Meta.log_subtype == 'zm_bad_password'"6groupby: "evt.Meta.source_ip"7capacity: 48leakspeed: "10s"9blackhole: 1m10labels:11 service: zoneminder12 type: bruteforce13 spoofable: 014 confidence: 315 remediation: true16 classification:17 - attack.T111018 behavior: "http:bruteforce"19 label: "Zoneminder bruteforce"20---21# user enum22type: leaky23name: baudneo/zoneminder-bf24description: "Detect ZoneMinder user enumeration"25filter: "evt.Meta.log_subtype == 'zm_bad_user'"26groupby: "evt.Meta.source_ip"27distinct: "evt.Meta.username"28capacity: 429leakspeed: "10s"30blackhole: 1m31labels:32 service: zoneminder33 type: bruteforce34 spoofable: 035 confidence: 336 remediation: true37 classification:38 - attack.T158939 - attack.T111040 behavior: "http:bruteforce"41 label: "Zoneminder user enumeration"42