Skip to content

Instantly share code, notes, and snippets.

@LaurenceJJones
Last active October 19, 2022 18:10
Show Gist options
  • Save LaurenceJJones/17edb251cad80efb9c573812ef90297f to your computer and use it in GitHub Desktop.
Save LaurenceJJones/17edb251cad80efb9c573812ef90297f to your computer and use it in GitHub Desktop.
{{ $list := dict "crowdsecurity/apache_log4j2_cve-2021-44228" "15,21" "jusabatier/apereo-cas-bf" "15,18" "jusabatier/apereo-cas-slow-bf" "15,18" "crowdsecurity/asterisk_bf" "15,18" "crowdsecurity/asterisk_user_enum" "15,18" "lepresidente/authelia-bf" "15,18" "crowdsecurity/ban-defcon-drop_range" "15,18" "jusabatier/cas-slow-bf" "15,18" "crowdsecurity/cpanel-bf" "15,18" "crowdsecurity/cpanel-bf-attempt" "15,18" "crowdsecurity/CVE-2021-4034" "15" "crowdsecurity/CVE-2022-37042" "15,21" "crowdsecurity/dovecot-spam" "11" "lepresidente/emby-bf" "15,18" "crowdsecurity/endlessh-bf" "15,18,22" "crowdsecurity/exchange-bf" "15,18" "crowdsecurity/f5-big-ip-cve-2020-5902" "15,21" "crowdsecurity/fortinet-cve-2018-13379" "15,21" "lepresidente/gitea-bf" "15,18" "timokoessler/gitlab-bf" "15,18" "baudneo/gotify-bf" "15,18" "crowdsecurity/grafana-cve-2021-43798" "15,21" "crowdsecurity/home-assistant-bf" "15,18" "crowdsecurity/http-apiscp-bf" "15,18" "crowdsecurity/http-backdoors-attempts" "15,21" "crowdsecurity/http-bad-user-agent" "14,19" "crowdsecurity/http-bf-wordpress_bf" "15,18" "crowdsecurity/http-bf-wordpress_bf_xmlrpc" "15,18" "crowdsecurity/http-crawl-non_statics" "19" "crowdsecurity/http-cve-2021-41773" "15,21" "crowdsecurity/http-cve-2021-42013" "15,21" "crowdsecurity/http-generic-bf" "15,18" "crowdsecurity/http-open-proxy" "9" "crowdsecurity/http-path-traversal-probing" "15,21" "crowdsecurity/http-probing" "21" "crowdsecurity/http-sensitive-files" "19" "crowdsecurity/http-sqli-probing" "19" "ltsich/http-w00tw00t" "14" "crowdsecurity/http-wordpress_user-enum" "15,18" "crowdsecurity/http-wordpress_wpconfig" "15,19" "crowdsecurity/http-xss-probing" "15,21" "crowdsecurity/iptables-scan-multi_ports" "14" "lepresidente/jellyseerr-bf" "15,18" "crowdsecurity/jira_cve-2021-26086" "15,21" "firewallservices/lemonldap-ng-bf" "15,18" "crowdsecurity/litespeed-admin-bf" "15,18" "hitech95/mail-generic-bf" "15,18" "crowdsecurity/mariadb-bf" "15,18" "crowdsecurity/modsecurity" "15" "timokoessler/mongodb-bf" "15,18" "crowdsecurity/mssql-bf" "15,18" "crowdsecurity/mysql-bf" "15,18" "crowdsecurity/naxsi-exploit-vpatch" "15" "crowdsecurity/nextcloud-bf" "15,18" "crowdsecurity/nginx-req-limit-exceeded" "19" "crowdsecurity/odoo-bf_user-enum" "15,18" "lepresidente/ombi-bf" "15,18" "crowdsecurity/opnsense-gui-bf" "15,18" "firewallservices/pf-scan-multi_ports" "14" "crowdsecurity/pgsql-bf" "15,18" "crowdsecurity/postfix-spam" "11" "crowdsecurity/proftpd-bf" "15,18" "crowdsecurity/proftpd-bf_user-enum" "15,18" "fulljackz/proxmox-bf" "15,18" "lourys/pterodactyl-wings-bf" "15,18" "crowdsecurity/pulse-secure-sslvpn-cve-2019-11510" "15,21" "fulljackz/pureftpd-bf" "15,18" "crowdsecurity/smb-bf" "15,18" "crowdsecurity/spring4shell_cve-2022-22965" "15,21" "crowdsecurity/ssh-bf" "15,18,22" "crowdsecurity/ssh-slow-bf" "15,18,22" "thespad/sshesame-honeypot" "15,18,22" "crowdsecurity/suricata-alerts" "15" "crowdsecurity/synology-dsm-bf" "15,18" "crowdsecurity/telnet-bf" "15,18" "crowdsecurity/thinkphp-cve-2018-20062" "15,21" "timokoessler/uptime-kuma-bf" "15,18" "dominic-wagner/vaultwarden-bf" "15,18" "crowdsecurity/vmware-cve-2022-22954" "15" "crowdsecurity/vmware-vcenter-vmsa-2021-0027" "15" "crowdsecurity/vsftpd-bf" "15,18" "crowdsecurity/windows-bf" "15,18" "crowdsecurity/windows-CVE-2022-30190-msdt" "15" "firewallservices/zimbra-bf" "15,18" "baudneo/zoneminder-bf" "15,18" -}}
{{range .}}
ip={{.Source.Value}}&comment=[Crowdsec]: detected via: {{ .Scenario }}&categories={{ get $list .Scenario }}
{{end}}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment