cscli scenarios install crowdsecurity/nginx-req-limit-exceeded
Detects IPs which violate nginx's user set request limit.
IP is banned if it violates nginx's user set request limit more than 5 times in a minute.
1type: leaky2#debug: true3name: crowdsecurity/nginx-req-limit-exceeded4description: "Detects IPs which violate nginx's user set request limit."5filter: evt.Meta.sub_type == 'req_limit_exceeded'6leakspeed: "60s"7capacity: 58groupby: evt.Meta.source_ip9blackhole: 5m10labels:11 remediation: true12 confidence: 213 spoofable: 214 classification:15 - attack.T149816 behavior: "http:dos"17 label: "Nginx request limit exceeded"18 service: http19