cscli scenarios install fulljackz/proxmox-bf
Detect failed proxmox authentications :
1# Proxmox authent bruteforce2type: leaky3name: fulljackz/proxmox-bf4description: "Detect proxmox bruteforce"5filter: "evt.Meta.log_type == 'pve_failed-auth'"6leakspeed: "10s"7capacity: 58groupby: evt.Meta.source_ip9blackhole: 1m10reprocess: true1112labels:13 service: vm-management14 confidence: 315 spoofable: 016 classification:17 - attack.T111018 behavior: "vm-management:bruteforce"19 label: "PveDaemon Bruteforce"20 remediation: true21---22# Proxmox bad user23type: leaky24name: fulljackz/proxmox-bf-user-enum25description: "Detect proxmox wrong username"26filter: "evt.Meta.log_type == 'pve_failed-auth'"27leakspeed: "10s"28capacity: 529groupby: evt.Meta.source_ip30distinct: evt.Meta.source_user31blackhole: 1m32reprocess: true33labels:34 service: vm-management35 confidence: 336 spoofable: 037 classification:38 - attack.T158939 - attack.T111040 behavior: "vm-management:bruteforce"41 label: "PveDaemon User Enum Bruteforce"42 remediation: true43