cscli scenarios install corvese/apache-guacamole_user_enum
Defends against user enumeration attack
1type: leaky2name: corvese/apache-guacamole_user_enum3description: "Detect Apache Guacamole user enum bruteforce"4filter: evt.Meta.log_type == 'apache-guacamole_failed_auth'5groupby: evt.Meta.source_ip6distinct: evt.Meta.target_user7leakspeed: 10s8capacity: 59blackhole: 1m10labels:11 service: apache-guacamole12 confidence: 313 spoofable: 014 classification:15 - attack.T158916 - attack.T111017 behavior: "http:bruteforce"18 label: "Apache Guacamole User Enumeration"19 remediation: true20