cscli scenarios install darkclip/charon-ipsec-slow-bf
Detects slow bruteforce authentications for Charon IPsec server.
1name: darkclip/charon-ipsec-bf2#debug: true3description: "Detect Charon IPsec slow bruteforce"4filter: "evt.Meta.log_type == 'charon_ipsec_auth_fail'"5type: leaky6groupby: evt.Meta.source_ip7leakspeed: "60s"8capacity: 109blackhole: 1m10labels:11 service: charon_ipsec12 behavior: "generic:bruteforce"13 classification:14 - attack.T111015 spoofable: 016 confidence: 317 label: "Charon IPsec Slow Bruteforce"18 remediation: true19