Files
zira-etc/crowdsec/hub/scenarios/crowdsecurity/mysql-bf.yaml
2023-06-12 09:31:52 +03:00

15 lines
293 B
YAML

# mysql bruteforce
type: leaky
#debug: true
name: crowdsecurity/mysql-bf
description: "Detect mysql bruteforce"
filter: evt.Meta.log_type == 'mysql_failed_auth'
leakspeed: "10s"
capacity: 5
groupby: evt.Meta.source_ip
blackhole: 5m
labels:
service: mysql
type: bruteforce
remediation: true