cscli scenarios install cbrandlehner/mailscanner-blacklisted1name: cbrandlehner/mailscanner-blacklisted2description: Detects MailScanner logs where a message is marked as spam due to blacklisting3type: trigger4filter: "evt.Meta.log_type == 'mailscanner_blacklist' && evt.Parsed.spam_reason == 'blacklisted'"5groupby: evt.Parsed.source_ip6blackhole: 5m7labels:8 type: spam9 remediation: true10 behavior: "smtp:spam"11 spoofable: 012 confidence: 213 label: "MailScanner detected an SMTP message from a blacklisted sender"14 service: smtp1516