cscli scenarios install gauth-fr/immich-bf
Detect failed Immich authentications:
1# immich BF scan2name: gauth-fr/immich-bf3description: "Detect immich bruteforce"4filter: "evt.Meta.log_type == 'immich_failed_auth'"5#debug: true6type: leaky7groupby: evt.Meta.source_ip8leakspeed: "20s"9capacity: 510blackhole: 1m11labels:12 service: immich13 confidence: 314 spoofable: 015 classification:16 - attack.T111017 label: "Immich Bruteforce"18 behavior: "http:bruteforce"19 remediation: true20---21# immich user-enum22type: leaky23name: gauth-fr/immich-bf_user-enum24description: "Detect immich user enum bruteforce"25filter: "evt.Meta.log_type == 'immich_failed_auth'"26groupby: evt.Meta.source_ip27distinct: evt.Meta.user28leakspeed: 10s29capacity: 530blackhole: 1m31labels:32 service: immich33 confidence: 334 spoofable: 035 classification:36 - attack.T158937 label: "Immich Bruteforce"38 behavior: "http:bruteforce"39 remediation: true40