cscli scenarios install pserranoa/openvpn-bf1# openvpn bruteforce detection / auth_failed2type: leaky3name: pserranoa/openvpn-bf4description: "Detect openvpn bruteforce"5filter: "evt.Meta.service == 'openvpn' && evt.Meta.log_type == 'auth_failed'"6leakspeed: "1m"7blackhole: 5m8capacity: 39groupby: evt.Meta.source_ip10reprocess: true11labels:12 service: openvpn13 remediation: true14 confidence: 315 spoofable: 016 classification:17 - attack.T111018 label: "OpenVPN Bruteforce"19 behaviour: "generic:bruteforce"20