cscli scenarios install crowdsecurity/fortinet-cve-2018-133791type: trigger2format: 2.03name: crowdsecurity/fortinet-cve-2018-133794description: "Detect cve-2018-13379 exploitation attemps"5filter: |6 evt.Meta.log_type in ["http_access-log", "http_error-log"] and7 Upper(evt.Meta.http_path) contains Upper('/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession')8groupby: "evt.Meta.source_ip"9blackhole: 2m10labels:11 confidence: 312 spoofable: 013 classification:14 - attack.T119015 - attack.T159516 - cve.CVE-2018-1337917 behavior: "http:exploit"18 label: "CVE-2018-13379"19 remediation: true20 service: fortinet21