cscli scenarios install jbowdre/miniflux-bf
Detect failed Miniflux authentications:
1# miniflux BF scan2name: jbowdre/miniflux-bf3description: "Detect miniflux bruteforce"4filter: "evt.Meta.log_type == 'miniflux_failed_auth'"5type: leaky6groupby: evt.Meta.source_ip7leakspeed: 20s8capacity: 59blackhole: 1m10labels:11 service: miniflux12 confidence: 313 spoofable: 014 classification:15 - attack.T111016 label: "Miniflux Bruteforce"17 behavior: "http:bruteforce"18 remediation: true19---20# miniflux user-enum21type: leaky22name: jbowdre/miniflux-bf_user-enum23description: "Detect miniflux user enum bruteforce"24filter: "evt.Meta.log_type == 'miniflux_failed_auth'"25groupby: evt.Meta.source_ip26distinct: evt.Meta.user27leakspeed: 1m28capacity: 529blackhole: 1m30labels:31 service: miniflux32 confidence: 333 spoofable: 034 classification:35 - attack.T158936 label: "Miniflux Bruteforce"37 behavior: "http:bruteforce"38 remediation: true3940