cscli scenarios install jusabatier/apereo-cas-slow-bf
Detect slow CAS bruteforce authentications :
1# CAS bruteforce2type: leaky3name: jusabatier/cas-slow-bf4description: "Detect slow CAS bruteforce"5filter: "evt.Meta.log_type == 'cas_failed-auth'"6leakspeed: "60s"7references:8 - http://wikipedia.com/cas-bf-is-bad9capacity: 1010groupby: evt.Meta.source_ip11blackhole: 1m12reprocess: true13labels:14 service: http15 confidence: 316 spoofable: 017 classification:18 - attack.T111019 behavior: "http:bruteforce"20 label: "CAS Slow Bruteforce"21 remediation: true22---23# cas user-enum24type: leaky25name: jusabatier/cas-slow-bf_user-enum26description: "Detect slow CAS user enum bruteforce"27filter: evt.Meta.log_type == 'cas_failed-auth'28groupby: evt.Meta.source_ip29distinct: evt.Meta.target_user30leakspeed: 60s31capacity: 1032blackhole: 1m33labels:34 service: http35 confidence: 336 spoofable: 037 classification:38 - attack.T158939 - attack.T111040 behavior: "http:bruteforce"41 label: "CAS Slow User Enum Bruteforce"42 remediation: true43