cscli scenarios install plague-doctor/audiobookshelf-bf
Detect failed Audiobookshelf authentications:
1# Audiobookshelf bruteforce2type: leaky3name: plague-doctor/audiobookshelf-bf4description: "Detect Audiobookshelf bruteforce attacks"5filter: "evt.Meta.service == 'audiobookshelf' && evt.Meta.log_type == 'abs_failed_auth'"6leakspeed: 1m7capacity: 38groupby: evt.Meta.source_ip9blackhole: 5m10reprocess: true11labels:12 service: audiobookshelf13 type: bruteforce14 classification:15 - attack.T111016 remediation: true17 behavior: http:bruteforce18 spoofable: 019 confidence: 320