d8dc01cd94
* Revamp unit tests * Increase coverage * Use go-acc to get cross packages coverage Signed-off-by: Shivam Sandbhor <shivam.sandbhor@gmail.com>
548 lines
No EOL
12 KiB
JSON
548 lines
No EOL
12 KiB
JSON
[
|
|
{
|
|
"capacity": 5,
|
|
"decisions": null,
|
|
"events": [
|
|
{
|
|
"meta": [
|
|
{
|
|
"key": "ASNOrg",
|
|
"value": "OVH SAS"
|
|
},
|
|
{
|
|
"key": "SourceRange",
|
|
"value": "91.121.72.0/21"
|
|
},
|
|
{
|
|
"key": "target_user",
|
|
"value": "root"
|
|
},
|
|
{
|
|
"key": "source_ip",
|
|
"value": "91.121.79.179"
|
|
},
|
|
{
|
|
"key": "IsoCode",
|
|
"value": "FR"
|
|
},
|
|
{
|
|
"key": "ASNNumber",
|
|
"value": "16276"
|
|
},
|
|
{
|
|
"key": "service",
|
|
"value": "ssh"
|
|
},
|
|
{
|
|
"key": "log_type",
|
|
"value": "ssh_failed-auth"
|
|
},
|
|
{
|
|
"key": "IsInEU",
|
|
"value": "true"
|
|
}
|
|
],
|
|
"timestamp": "2020-10-02T17:09:08Z"
|
|
},
|
|
{
|
|
"meta": [
|
|
{
|
|
"key": "source_ip",
|
|
"value": "91.121.79.179"
|
|
},
|
|
{
|
|
"key": "IsoCode",
|
|
"value": "FR"
|
|
},
|
|
{
|
|
"key": "log_type",
|
|
"value": "ssh_failed-auth"
|
|
},
|
|
{
|
|
"key": "service",
|
|
"value": "ssh"
|
|
},
|
|
{
|
|
"key": "IsInEU",
|
|
"value": "true"
|
|
},
|
|
{
|
|
"key": "ASNNumber",
|
|
"value": "16276"
|
|
},
|
|
{
|
|
"key": "ASNOrg",
|
|
"value": "OVH SAS"
|
|
},
|
|
{
|
|
"key": "SourceRange",
|
|
"value": "91.121.72.0/21"
|
|
},
|
|
{
|
|
"key": "target_user",
|
|
"value": "root"
|
|
}
|
|
],
|
|
"timestamp": "2020-10-02T17:09:08Z"
|
|
},
|
|
{
|
|
"meta": [
|
|
{
|
|
"key": "target_user",
|
|
"value": "root"
|
|
},
|
|
{
|
|
"key": "IsInEU",
|
|
"value": "true"
|
|
},
|
|
{
|
|
"key": "ASNNumber",
|
|
"value": "16276"
|
|
},
|
|
{
|
|
"key": "service",
|
|
"value": "ssh"
|
|
},
|
|
{
|
|
"key": "log_type",
|
|
"value": "ssh_failed-auth"
|
|
},
|
|
{
|
|
"key": "source_ip",
|
|
"value": "91.121.79.179"
|
|
},
|
|
{
|
|
"key": "IsoCode",
|
|
"value": "FR"
|
|
},
|
|
{
|
|
"key": "ASNOrg",
|
|
"value": "OVH SAS"
|
|
},
|
|
{
|
|
"key": "SourceRange",
|
|
"value": "91.121.72.0/21"
|
|
}
|
|
],
|
|
"timestamp": "2020-10-02T17:09:08Z"
|
|
},
|
|
{
|
|
"meta": [
|
|
{
|
|
"key": "ASNNumber",
|
|
"value": "16276"
|
|
},
|
|
{
|
|
"key": "ASNOrg",
|
|
"value": "OVH SAS"
|
|
},
|
|
{
|
|
"key": "service",
|
|
"value": "ssh"
|
|
},
|
|
{
|
|
"key": "source_ip",
|
|
"value": "91.121.79.179"
|
|
},
|
|
{
|
|
"key": "IsoCode",
|
|
"value": "FR"
|
|
},
|
|
{
|
|
"key": "SourceRange",
|
|
"value": "91.121.72.0/21"
|
|
},
|
|
{
|
|
"key": "target_user",
|
|
"value": "root"
|
|
},
|
|
{
|
|
"key": "log_type",
|
|
"value": "ssh_failed-auth"
|
|
},
|
|
{
|
|
"key": "IsInEU",
|
|
"value": "true"
|
|
}
|
|
],
|
|
"timestamp": "2020-10-02T17:09:08Z"
|
|
},
|
|
{
|
|
"meta": [
|
|
{
|
|
"key": "SourceRange",
|
|
"value": "91.121.72.0/21"
|
|
},
|
|
{
|
|
"key": "target_user",
|
|
"value": "root"
|
|
},
|
|
{
|
|
"key": "service",
|
|
"value": "ssh"
|
|
},
|
|
{
|
|
"key": "log_type",
|
|
"value": "ssh_failed-auth"
|
|
},
|
|
{
|
|
"key": "source_ip",
|
|
"value": "91.121.79.179"
|
|
},
|
|
{
|
|
"key": "IsoCode",
|
|
"value": "FR"
|
|
},
|
|
{
|
|
"key": "IsInEU",
|
|
"value": "true"
|
|
},
|
|
{
|
|
"key": "ASNNumber",
|
|
"value": "16276"
|
|
},
|
|
{
|
|
"key": "ASNOrg",
|
|
"value": "OVH SAS"
|
|
}
|
|
],
|
|
"timestamp": "2020-10-02T17:09:08Z"
|
|
},
|
|
{
|
|
"meta": [
|
|
{
|
|
"key": "log_type",
|
|
"value": "ssh_failed-auth"
|
|
},
|
|
{
|
|
"key": "source_ip",
|
|
"value": "91.121.79.179"
|
|
},
|
|
{
|
|
"key": "ASNNumber",
|
|
"value": "16276"
|
|
},
|
|
{
|
|
"key": "ASNOrg",
|
|
"value": "OVH SAS"
|
|
},
|
|
{
|
|
"key": "SourceRange",
|
|
"value": "91.121.72.0/21"
|
|
},
|
|
{
|
|
"key": "target_user",
|
|
"value": "root"
|
|
},
|
|
{
|
|
"key": "service",
|
|
"value": "ssh"
|
|
},
|
|
{
|
|
"key": "IsoCode",
|
|
"value": "FR"
|
|
},
|
|
{
|
|
"key": "IsInEU",
|
|
"value": "true"
|
|
}
|
|
],
|
|
"timestamp": "2020-10-02T17:09:08Z"
|
|
}
|
|
],
|
|
"events_count": 6,
|
|
"labels": null,
|
|
"leakspeed": "10s",
|
|
"message": "Ip 91.121.79.179 performed crowdsecurity/ssh-bf (6 events over 46.375699ms) at 2020-10-26 12:52:58.200237122 +0100 CET m=+8.191478202",
|
|
"remediation": true,
|
|
"scenario": "crowdsecurity/ssh-bf",
|
|
"scenario_hash": "4441dcff07020f6690d998b7101e642359ba405c2abb83565bbbdcee36de280f",
|
|
"scenario_version": "0.1",
|
|
"simulated": false,
|
|
"source": {
|
|
"as_name": "OVH SAS",
|
|
"cn": "FR",
|
|
"ip": "91.121.79.179",
|
|
"latitude": 50.646,
|
|
"longitude": 3.0758,
|
|
"range": "91.121.72.0/21",
|
|
"scope": "Ip",
|
|
"value": "91.121.79.179"
|
|
},
|
|
"start_at": "2020-10-26T12:52:58.153861334+01:00",
|
|
"stop_at": "2020-10-26T12:52:58.200236582+01:00"
|
|
},
|
|
{
|
|
"capacity": 5,
|
|
"decisions": null,
|
|
"events": [
|
|
{
|
|
"meta": [
|
|
{
|
|
"key": "ASNOrg",
|
|
"value": "OVH SAS"
|
|
},
|
|
{
|
|
"key": "SourceRange",
|
|
"value": "91.121.72.0/21"
|
|
},
|
|
{
|
|
"key": "target_user",
|
|
"value": "root"
|
|
},
|
|
{
|
|
"key": "source_ip",
|
|
"value": "91.121.79.178"
|
|
},
|
|
{
|
|
"key": "IsoCode",
|
|
"value": "FR"
|
|
},
|
|
{
|
|
"key": "ASNNumber",
|
|
"value": "16276"
|
|
},
|
|
{
|
|
"key": "service",
|
|
"value": "ssh"
|
|
},
|
|
{
|
|
"key": "log_type",
|
|
"value": "ssh_failed-auth"
|
|
},
|
|
{
|
|
"key": "IsInEU",
|
|
"value": "true"
|
|
}
|
|
],
|
|
"timestamp": "2020-10-02T17:09:08Z"
|
|
},
|
|
{
|
|
"meta": [
|
|
{
|
|
"key": "source_ip",
|
|
"value": "91.121.79.178"
|
|
},
|
|
{
|
|
"key": "IsoCode",
|
|
"value": "FR"
|
|
},
|
|
{
|
|
"key": "log_type",
|
|
"value": "ssh_failed-auth"
|
|
},
|
|
{
|
|
"key": "service",
|
|
"value": "ssh"
|
|
},
|
|
{
|
|
"key": "IsInEU",
|
|
"value": "true"
|
|
},
|
|
{
|
|
"key": "ASNNumber",
|
|
"value": "16276"
|
|
},
|
|
{
|
|
"key": "ASNOrg",
|
|
"value": "OVH SAS"
|
|
},
|
|
{
|
|
"key": "SourceRange",
|
|
"value": "91.121.72.0/21"
|
|
},
|
|
{
|
|
"key": "target_user",
|
|
"value": "root"
|
|
}
|
|
],
|
|
"timestamp": "2020-10-02T17:09:08Z"
|
|
},
|
|
{
|
|
"meta": [
|
|
{
|
|
"key": "target_user",
|
|
"value": "root"
|
|
},
|
|
{
|
|
"key": "IsInEU",
|
|
"value": "true"
|
|
},
|
|
{
|
|
"key": "ASNNumber",
|
|
"value": "16276"
|
|
},
|
|
{
|
|
"key": "service",
|
|
"value": "ssh"
|
|
},
|
|
{
|
|
"key": "log_type",
|
|
"value": "ssh_failed-auth"
|
|
},
|
|
{
|
|
"key": "source_ip",
|
|
"value": "91.121.79.178"
|
|
},
|
|
{
|
|
"key": "IsoCode",
|
|
"value": "FR"
|
|
},
|
|
{
|
|
"key": "ASNOrg",
|
|
"value": "OVH SAS"
|
|
},
|
|
{
|
|
"key": "SourceRange",
|
|
"value": "91.121.72.0/21"
|
|
}
|
|
],
|
|
"timestamp": "2020-10-02T17:09:08Z"
|
|
},
|
|
{
|
|
"meta": [
|
|
{
|
|
"key": "ASNNumber",
|
|
"value": "16276"
|
|
},
|
|
{
|
|
"key": "ASNOrg",
|
|
"value": "OVH SAS"
|
|
},
|
|
{
|
|
"key": "service",
|
|
"value": "ssh"
|
|
},
|
|
{
|
|
"key": "source_ip",
|
|
"value": "91.121.79.178"
|
|
},
|
|
{
|
|
"key": "IsoCode",
|
|
"value": "FR"
|
|
},
|
|
{
|
|
"key": "SourceRange",
|
|
"value": "91.121.72.0/21"
|
|
},
|
|
{
|
|
"key": "target_user",
|
|
"value": "root"
|
|
},
|
|
{
|
|
"key": "log_type",
|
|
"value": "ssh_failed-auth"
|
|
},
|
|
{
|
|
"key": "IsInEU",
|
|
"value": "true"
|
|
}
|
|
],
|
|
"timestamp": "2020-10-02T17:09:08Z"
|
|
},
|
|
{
|
|
"meta": [
|
|
{
|
|
"key": "SourceRange",
|
|
"value": "91.121.72.0/21"
|
|
},
|
|
{
|
|
"key": "target_user",
|
|
"value": "root"
|
|
},
|
|
{
|
|
"key": "service",
|
|
"value": "ssh"
|
|
},
|
|
{
|
|
"key": "log_type",
|
|
"value": "ssh_failed-auth"
|
|
},
|
|
{
|
|
"key": "source_ip",
|
|
"value": "91.121.79.178"
|
|
},
|
|
{
|
|
"key": "IsoCode",
|
|
"value": "FR"
|
|
},
|
|
{
|
|
"key": "IsInEU",
|
|
"value": "true"
|
|
},
|
|
{
|
|
"key": "ASNNumber",
|
|
"value": "16276"
|
|
},
|
|
{
|
|
"key": "ASNOrg",
|
|
"value": "OVH SAS"
|
|
}
|
|
],
|
|
"timestamp": "2020-10-02T17:09:08Z"
|
|
},
|
|
{
|
|
"meta": [
|
|
{
|
|
"key": "log_type",
|
|
"value": "ssh_failed-auth"
|
|
},
|
|
{
|
|
"key": "source_ip",
|
|
"value": "91.121.79.178"
|
|
},
|
|
{
|
|
"key": "ASNNumber",
|
|
"value": "16276"
|
|
},
|
|
{
|
|
"key": "ASNOrg",
|
|
"value": "OVH SAS"
|
|
},
|
|
{
|
|
"key": "SourceRange",
|
|
"value": "91.121.72.0/21"
|
|
},
|
|
{
|
|
"key": "target_user",
|
|
"value": "root"
|
|
},
|
|
{
|
|
"key": "service",
|
|
"value": "ssh"
|
|
},
|
|
{
|
|
"key": "IsoCode",
|
|
"value": "FR"
|
|
},
|
|
{
|
|
"key": "IsInEU",
|
|
"value": "true"
|
|
}
|
|
],
|
|
"timestamp": "2020-10-02T17:09:08Z"
|
|
}
|
|
],
|
|
"events_count": 6,
|
|
"labels": null,
|
|
"leakspeed": "10s",
|
|
"message": "Ip 91.121.79.178 performed crowdsecurity/ssh-bf (6 events over 46.375699ms) at 2020-10-26 12:52:58.200237122 +0100 CET m=+8.191478202",
|
|
"remediation": true,
|
|
"scenario": "crowdsecurity/ssh-bf",
|
|
"scenario_hash": "4441dcff07020f6690d998b7101e642359ba405c2abb83565bbbdcee36de280f",
|
|
"scenario_version": "0.1",
|
|
"simulated": false,
|
|
"source": {
|
|
"as_name": "OVH SAS",
|
|
"cn": "FR",
|
|
"ip": "91.121.79.178",
|
|
"latitude": 50.646,
|
|
"longitude": 3.0758,
|
|
"range": "91.121.72.0/21",
|
|
"scope": "Ip",
|
|
"value": "91.121.79.178"
|
|
},
|
|
"start_at": "2020-10-26T12:52:58.153861334+01:00",
|
|
"stop_at": "2020-10-26T12:52:58.200236582+01:00"
|
|
}
|
|
] |