cscli scenarios install crowdsecurity/asterisk_user_enum
1type: leaky2name: crowdsecurity/asterisk_user_enum3description: "Detect Asterisk user enumeration bruteforce"4filter: evt.Meta.log_type == 'asterisk_failed_auth'5groupby: evt.Meta.source_ip6distinct: evt.Meta.target_user7leakspeed: 10s8capacity: 59blackhole: 1m10labels:11 service: asterisk12 confidence: 313 spoofable: 014 classification:15 - attack.T108716 - attack.T1589.00117 - attack.T111018 behavior: "sip:bruteforce"19 label: "Asterisk User Enumeration"20 remediation: true21