cscli appsec-rules install crowdsecurity/vpatch-connectwise-auth-bypass1name: crowdsecurity/vpatch-connectwise-auth-bypass2description: "Detect exploitation of auth bypass in ConnectWise ScreenConnect"3rules:4 - zones:5 - URI6 transform:7 - lowercase8 match:9 type: endsWith10 value: /setupwizard.aspx/11labels:12 type: exploit13 service: http14 confidence: 315 spoofable: 016 behavior: "http:exploit"17 label: "ConnectWise ScreenConnect - Authentication Bypass"18 classification:19 - attack.T159520 - attack.T119021 - cve.CVE-2024-170922