Files
zira-etc/crowdsec/patterns/smb
2023-06-12 09:31:52 +03:00

1 line
173 B
Plaintext

SMB_AUTH_FAIL Auth:%{GREEDYDATA} user \[%{DATA:smb_domain}\]\\\[%{DATA:user}\]%{GREEDYDATA} status \[NT_STATUS_NO_SUCH_USER\]%{GREEDYDATA} remote host \[ipv4:%{IP:ip_source}