cscli scenarios install firewallservices/zimbra-bf
Detect various authentication failures on Zimbra
This scenario uses two leaky buckets:
1# Zimbra brutforce2type: leaky3#debug: true4name: firewallservices/zimbra-bf5description: "Detect Zimbra bruteforce"6filter: evt.Meta.log_type == 'zimbra_auth_fail'7leakspeed: 30s8capacity: 59groupby: evt.Meta.source_ip10blackhole: 1m11reprocess: true12labels:13 service: zimbra14 confidence: 315 spoofable: 016 classification:17 - attack.T111018 behavior: "pop3/imap:bruteforce"19 label: "Zimbra Bruteforce"20 remediation: true21---22# Zimbra user enumeration23type: leaky24#debug: true25name: firewallservices/zimbra-user-enum26description: "Detect Zimbra user enum bruteforce"27filter: evt.Meta.log_type == 'zimbra_auth_fail'28groupby: evt.Meta.source_ip29distinct: evt.Meta.user30leakspeed: 2m31capacity: 532blackhole: 1m33labels:34 service: zimbra35 confidence: 336 spoofable: 037 classification:38 - attack.T1589.00239 - attack.T111040 behavior: "pop3/imap:bruteforce"41 label: "Zimbra Bruteforce"42 remediation: true43