cscli scenarios install crowdsecurity/crowdsec-appsec-outofband
1type: leaky2filter: evt.Parsed.source == 'crowdsec-appsec' && evt.Appsec.HasOutBandMatches == true && evt.Parsed.outofband_action in ["deny", "drop"]3name: crowdsecurity/crowdsec-appsec-outofband4description: IP has made more than 5 requests that triggered out-of-band appsec rules5blackhole: 2m6leakspeed: 30s7capacity: 58labels:9 type: exploit10 behavior: "http:exploit"11 remediation: true12 confidence: 113 spoofable: 014 classification:15 - attack.T119016 label: "Triggered multiple OutOfBand CrowdSec AppSec rules"17 service: http18groupby: "evt.Meta.source_ip"19#---20# at least requests blocked on 3 distinct URIs21#type: leaky22#filter: evt.Parsed.source == 'crowdsec-appsec' && evt.Appsec.HasOutBandMatches == true && evt.Parsed.outofband_action in ["deny", "drop"]23#name: crowdsecurity/waf-probing24#description: "WAF probing"25#blackhole: 2m26#leakspeed: 60s27#capacity: 528#groupby: "evt.Meta.source_ip + evt.Parsed.target_uri"29#labels:30# type: exploit31# remediation: true32