mirror of
https://github.com/aykhans/my-self-host-services.git
synced 2026-05-29 15:35:59 +00:00
add crowdsec
This commit is contained in:
@@ -0,0 +1,13 @@
|
||||
type: leaky
|
||||
name: aykhans/stalwart-auth-bruteforce
|
||||
description: Detect SMTP/IMAP/POP3 authentication brute force on Stalwart
|
||||
filter: |
|
||||
evt.Parsed.event_type == "auth.failed"
|
||||
groupby: evt.Meta.source_ip
|
||||
capacity: 3
|
||||
leakspeed: 10m
|
||||
blackhole: 1h
|
||||
labels:
|
||||
type: bruteforce
|
||||
service: stalwart
|
||||
remediation: true
|
||||
@@ -0,0 +1,17 @@
|
||||
type: leaky
|
||||
name: stalwart/smtp-bruteforce
|
||||
description: Detect SMTP bruteforce and scanners on Stalwart logs
|
||||
filter: |
|
||||
evt.Parsed.event_type in [
|
||||
"smtp.invalid-ehlo",
|
||||
"smtp.auth-not-allowed",
|
||||
"smtp.auth-mechanism-not-supported"
|
||||
]
|
||||
groupby: evt.Meta.source_ip
|
||||
capacity: 5
|
||||
leakspeed: 10m
|
||||
blackhole: 1h
|
||||
labels:
|
||||
type: attack
|
||||
service: smtp
|
||||
remediation: true
|
||||
Reference in New Issue
Block a user