cscli scenarios install crowdsecurity/litespeed-admin-bf
Alert when a single IP that try to bruteforce litespeed admin UI.
Leakspeed of 10s, capacity of 5.
1type: leaky2name: crowdsecurity/litespeed-admin-bf3description: "Detect bruteforce against litespeed admin UI"4filter: "evt.Meta.service == 'http' && evt.Meta.sub_type == 'litespeed_admin_auth_fail'"5groupby: evt.Meta.source_ip6capacity: 57leakspeed: "10s"8blackhole: 1m9labels:10 remediation: true11 classification:12 - attack.T111013 behavior: "http:bruteforce"14 label: "LiteSpeed Admin Bruteforce"15 spoofable: 016 confidence: 317 service: litespeed18