cscli scenarios install inherent-io/keycloak-slow-bf
Detect failed Keycloak authentications :
1type: leaky2name: inherent-io/keycloak-slow-bf3description: "Detect keycloak bruteforce"4filter: evt.Meta.service == "keycloak" && evt.Meta.error in ['user_not_found', 'invalid_user_credentials']5leakspeed: "60s"6capacity: 107groupby: evt.Meta.source_ip8blackhole: 1m9reprocess: true10labels:11 service: keycloak12 confidence: 313 spoofable: 014 classification:15 - attack.T111016 label: "Keycloak Bruteforce"17 behavior: "http:bruteforce"18 remediation: true19---20type: leaky21name: inherent-io/keycloak-user-enum-slow-bf22description: "Detect keycloak user enum bruteforce"23filter: evt.Meta.service == "keycloak" && evt.Meta.error in ['user_not_found', 'invalid_user_credentials']24leakspeed: "60s"25capacity: 1026groupby: evt.Meta.source_ip27distinct: evt.Meta.username28blackhole: 1m29reprocess: true30labels:31 service: keycloak32 confidence: 333 spoofable: 034 classification:35 - attack.T158936 label: "Keycloak Bruteforce"37 behavior: "http:bruteforce"38 remediation: true39