cscli scenarios install crowdsecurity/postfix-spamContains multiple scenarios:
1# postfix spam2type: leaky3name: crowdsecurity/postfix-spam4description: "Detect spammers"5filter: "evt.Meta.log_type_enh == 'spam-attempt' || evt.Meta.log_type == 'postfix' && evt.Meta.action == 'reject'"6leakspeed: "10s"7references:8 - https://en.wikipedia.org/wiki/Spamming9capacity: 510groupby: evt.Meta.source_ip11blackhole: 1m12reprocess: false13labels:14 service: postfix15 remediation: true16 confidence: 317 spoofable: 018 behavior: "smtp:spam"19 label: "Postfix Spam"20---21# postfix spam22type: trigger23name: crowdsecurity/postscreen-rbl24description: "Detect spammers"25filter: "evt.Meta.service == 'postscreen' && evt.Meta.pregreet == 'PREGREET'"26references:27 - https://en.wikipedia.org/wiki/Spamming28groupby: evt.Meta.source_ip29blackhole: 1m30reprocess: false31labels:32 service: postscreen33 remediation: true34 confidence: 335 spoofable: 036 behavior: "smtp:spam"37 label: "Postfix Spam"38