Skip to content
This repository was archived by the owner on Nov 3, 2021. It is now read-only.

Add LDAP bruteforce alert#1473

Merged
pwnbus merged 9 commits intomasterfrom
ldap_bruteforce_alert
Oct 4, 2019
Merged

Add LDAP bruteforce alert#1473
pwnbus merged 9 commits intomasterfrom
ldap_bruteforce_alert

Conversation

@claudijd
Copy link
Copy Markdown
Contributor

@claudijd claudijd commented Sep 30, 2019

Makes use of soon to be deployed user attribute to offer per user bruteforce alerting in MozDef. This should stay as a WIP until we have verifiable data in prod with the exact formats to spec out.

@claudijd claudijd changed the title Add LDAP bruteforce alert [WIP] Add LDAP bruteforce alert Sep 30, 2019
@claudijd claudijd requested a review from jdow September 30, 2019 15:14
Comment thread alerts/ldap_bruteforce.py Outdated
@@ -0,0 +1,3 @@
[options]
threshold_count = 1
Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We need to set this to a higher value in prod, but we can use our data to support where exactly we should set this threshold per our specific environment.

@claudijd claudijd changed the title [WIP] Add LDAP bruteforce alert Add LDAP bruteforce alert Oct 2, 2019
@claudijd
Copy link
Copy Markdown
Contributor Author

claudijd commented Oct 2, 2019

@pwnbus this is ready, just not the config will need to be tweaked before deploying to prod.

@pwnbus pwnbus merged commit c8a9d94 into master Oct 4, 2019
@pwnbus pwnbus deleted the ldap_bruteforce_alert branch October 4, 2019 16:16
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants