Lets start another try

Trying again
main
Hailey Clark 4 years ago
parent ecbe22d752
commit 33402542bf
  1. 3
      collections/freeswitch.yaml
  2. 11
      parsers/s01-parse/freeswitch.yaml
  3. 2
      scenarios/freeswitch-bf.yaml

@ -1,10 +1,9 @@
parsers: parsers:
- haileyxb/freeswitch - haileyxb/freeswitch
scenarios: scenarios:
- haileyxb/freeswitch - haileyxb/freeswitch-bf
description: "freeswitch support : logs and brute-force scenarios" description: "freeswitch support : logs and brute-force scenarios"
author: haileyxb author: haileyxb
tags: tags:
- linux - linux
- freeswitch - freeswitch
- bruteforce

@ -2,14 +2,17 @@ onsuccess: next_stage
debug: true debug: true
name: haileyxb/freeswitch name: haileyxb/freeswitch
description: "Parse Freeswitch logs" description: "Parse Freeswitch logs"
filter: "evt.Parsed.program == 'freeswitch'" filter: evt.Parsed.program == 'freeswitch'
pattern_syntax:
FS_TIMESTAMP: '202[12]-[01][0-9]-[01]\d \d\d:\d\d:\d\d.\d+'
FS_EXTENSION: '\[[0-9a-zA-Z]+@107.170.213.226\]'
grok: grok:
pattern: \\"202[12]-[01][0-9]-[01]\d \d\d:\d\d:\d\d.\d\d\d\d\d\d \\[WARNING\\]sofia_reg.c:1739 SIP auth failure (REGISTER) on sofia profile 'internal' for \\[[0-9a-zA-Z]+@107.170.213.226\\] from ip {IP:source_ip}\\" pattern: ^%{FS_TIMESTAMP:timestamp} \[WARNING\]sofia_reg.c:1739 SIP auth failure (REGISTER) on sofia profile 'internal' for %{FS_EXTENSION:fs_exten} from ip %{IP:source_ip}$
apply_on: message apply_on: message
statics: statics:
- meta: log_type - meta: log_type
value: freeswitch_failed_auth value: freeswitch_failed_auth
- meta: source_ip - meta: source_ip
expression: "evt.Parsed.source_ip" expression: "evt.Parsed.source_ip"
- meta: user - meta: exten
expression: "evt.Parsed.user" expression: "evt.Parsed.fs_exten"

@ -11,4 +11,4 @@ blackhole: 10m
labels: labels:
service: freeswitch service: freeswitch
type: bruteforce type: bruteforce
remediation: true remediation: false
Loading…
Cancel
Save