type: leaky name: crowdsecurity/CVE-2022-41697 description: "Detect CVE-2022-41697 enumeration" filter: | Upper(evt.Meta.http_path) contains Upper('/ghost/api/admin/session') && Upper(evt.Parsed.verb) == 'POST' && evt.Meta.http_status == '404' leakspeed: "10s" capacity: 5 blackhole: 1m groupby: "evt.Meta.source_ip" labels: type: exploit remediation: true