зеркало из https://github.com/mozilla/MozDef.git
Merge pull request #666 from mozilla/ssh_bruteforce_improvement
Add publickey to TermsMatch
This commit is contained in:
Коммит
0cb3847703
|
@ -18,7 +18,7 @@ class AlertBruteforceSsh(AlertTask):
|
|||
search_query.add_must([
|
||||
PhraseMatch('summary', 'failed'),
|
||||
TermMatch('details.program', 'sshd'),
|
||||
TermsMatch('summary', ['login', 'invalid', 'ldap_count_entries'])
|
||||
TermsMatch('summary', ['login', 'invalid', 'ldap_count_entries', 'publickey'])
|
||||
])
|
||||
|
||||
for ip_address in self.config.skiphosts.split():
|
||||
|
|
Загрузка…
Ссылка в новой задаче