зеркало из https://github.com/mozilla/MozDef.git
Add publickey to TermsMatch as we are missing all publickey failed logins.
This commit is contained in:
Родитель
18504dca50
Коммит
3cf4b242fb
|
@ -18,7 +18,7 @@ class AlertBruteforceSsh(AlertTask):
|
|||
search_query.add_must([
|
||||
PhraseMatch('summary', 'failed'),
|
||||
TermMatch('details.program', 'sshd'),
|
||||
TermsMatch('summary', ['login', 'invalid', 'ldap_count_entries'])
|
||||
TermsMatch('summary', ['login', 'invalid', 'ldap_count_entries', 'publickey'])
|
||||
])
|
||||
|
||||
for ip_address in self.config.skiphosts.split():
|
||||
|
|
Загрузка…
Ссылка в новой задаче