Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Scenario taxonomy #736

Merged
merged 154 commits into from
Oct 6, 2023
Merged

Scenario taxonomy #736

merged 154 commits into from
Oct 6, 2023

Conversation

AlteredCoder
Copy link
Contributor

No description provided.

@crowdsecurity crowdsecurity deleted a comment from github-actions bot May 19, 2023
@crowdsecurity crowdsecurity deleted a comment from github-actions bot May 19, 2023
@crowdsecurity crowdsecurity deleted a comment from github-actions bot May 19, 2023
@crowdsecurity crowdsecurity deleted a comment from github-actions bot May 19, 2023
@crowdsecurity crowdsecurity deleted a comment from github-actions bot May 19, 2023
@crowdsecurity crowdsecurity deleted a comment from github-actions bot May 19, 2023
@crowdsecurity crowdsecurity deleted a comment from github-actions bot May 19, 2023
@crowdsecurity crowdsecurity deleted a comment from github-actions bot May 19, 2023
@crowdsecurity crowdsecurity deleted a comment from github-actions bot Sep 18, 2023
@crowdsecurity crowdsecurity deleted a comment from github-actions bot Sep 18, 2023
@github-actions
Copy link

andreasbrett/baikal-bf:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: baikal:bruteforce

andreasbrett/baikal-bf_user-enum:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: baikal:bruteforce

crowdsecurity/exim-spam:

  • attack not found in labels.classification

crowdsecurity/palo-alto-threat:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: :

crowdsecurity/postfix-spam:

  • attack not found in labels.classification

crowdsecurity/postscreen-rbl:

  • attack not found in labels.classification

Information about mitre attack can be found here.
As an example, some common mitre attack techniques:

  • T1110 for bruteforce attacks
  • T1595 and T1190 for exploitation of public vulnerabilities
  • T1595 for generic scanning of exposed applications

Here is the CrowdSec documentation on how to fill those labels

@github-actions
Copy link

andreasbrett/baikal-bf:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: baikal:bruteforce

andreasbrett/baikal-bf_user-enum:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: baikal:bruteforce

crowdsecurity/exim-spam:

  • attack not found in labels.classification

crowdsecurity/palo-alto-threat:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: :

crowdsecurity/postfix-spam:

  • attack not found in labels.classification

crowdsecurity/postscreen-rbl:

  • attack not found in labels.classification

Information about mitre attack can be found here.
As an example, some common mitre attack techniques:

  • T1110 for bruteforce attacks
  • T1595 and T1190 for exploitation of public vulnerabilities
  • T1595 for generic scanning of exposed applications

Here is the CrowdSec documentation on how to fill those labels

@github-actions
Copy link

andreasbrett/baikal-bf:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: baikal:bruteforce

andreasbrett/baikal-bf_user-enum:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: baikal:bruteforce

crowdsecurity/exim-spam:

  • attack not found in labels.classification

crowdsecurity/palo-alto-threat:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: :

crowdsecurity/postfix-spam:

  • attack not found in labels.classification

crowdsecurity/postscreen-rbl:

  • attack not found in labels.classification

Information about mitre attack can be found here.
As an example, some common mitre attack techniques:

  • T1110 for bruteforce attacks
  • T1595 and T1190 for exploitation of public vulnerabilities
  • T1595 for generic scanning of exposed applications

Here is the CrowdSec documentation on how to fill those labels

@github-actions
Copy link

github-actions bot commented Oct 6, 2023

crowdsecurity/exim-spam:

  • attack not found in labels.classification

crowdsecurity/palo-alto-threat:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: :

crowdsecurity/postfix-spam:

  • attack not found in labels.classification

crowdsecurity/postscreen-rbl:

  • attack not found in labels.classification

Information about mitre attack can be found here.
As an example, some common mitre attack techniques:

  • T1110 for bruteforce attacks
  • T1595 and T1190 for exploitation of public vulnerabilities
  • T1595 for generic scanning of exposed applications

Here is the CrowdSec documentation on how to fill those labels

@github-actions
Copy link

github-actions bot commented Oct 6, 2023

crowdsecurity/exim-spam:

  • attack not found in labels.classification

Information about mitre attack can be found here.
As an example, some common mitre attack techniques:

  • T1110 for bruteforce attacks
  • T1595 and T1190 for exploitation of public vulnerabilities
  • T1595 for generic scanning of exposed applications

Here is the CrowdSec documentation on how to fill those labels

@github-actions
Copy link

github-actions bot commented Oct 6, 2023

crowdsecurity/exim-spam:

  • attack not found in labels.classification

Information about mitre attack can be found here.
As an example, some common mitre attack techniques:

  • T1110 for bruteforce attacks
  • T1595 and T1190 for exploitation of public vulnerabilities
  • T1595 for generic scanning of exposed applications

Here is the CrowdSec documentation on how to fill those labels

@github-actions
Copy link

github-actions bot commented Oct 6, 2023

crowdsecurity/CVE-2023-4911:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: :

crowdsecurity/auditd-suid-crash:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: linux:exploitation

xs539/bookstack-bf:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: bookstack:bruteforce

xs539/bookstack-bf_user-enum:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: bookstack:bruteforce

xs539/joplin-server-bf:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: joplin:bruteforce

xs539/joplin-server-bf_user-enum:

  • attack not found in labels.classification
  • spoofable key not found in labels
  • confidence key not found in labels
  • Unknown behaviors: joplin:bruteforce

Information about mitre attack can be found here.
As an example, some common mitre attack techniques:

  • T1110 for bruteforce attacks
  • T1595 and T1190 for exploitation of public vulnerabilities
  • T1595 for generic scanning of exposed applications

Here is the CrowdSec documentation on how to fill those labels
Here are the available behaviors

@AlteredCoder AlteredCoder merged commit d4b0af9 into master Oct 6, 2023
@AlteredCoder AlteredCoder deleted the scenario_taxonomy branch October 6, 2023 13:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

9 participants