cscli scenarios install corvese/apache-guacamole_bf
Defends against a single user's account being bruteforced
1type: leaky2name: corvese/apache-guacamole_bf3description: "Detect Apache Guacamole user bruteforce"4filter: evt.Meta.log_type == 'apache-guacamole_failed_auth'5groupby: evt.Meta.source_ip6leakspeed: 10s7capacity: 58blackhole: 1m9labels:10 service: apache-guacamole11 confidence: 312 spoofable: 013 classification:14 - attack.T111015 behavior: "http:bruteforce"16 label: "Apache Guacamole Bruteforce"17 remediation: true18