Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- line: 104.131.183.68 - - [13/Feb/2025:00:47:15 +0000] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 Keydrop"
- ├ s00-raw
- | ├ 🔴 crowdsecurity/syslog-logs
- | └ 🟢 crowdsecurity/non-syslog (+5 ~8)
- ├ s01-parse
- | ├ 🔴 crowdsecurity/appsec-logs
- | ├ 🔴 crowdsecurity/auditd-logs
- | ├ 🔴 laurencejjones/dovecot-pam
- | ├ 🔴 crowdsecurity/dovecot-logs
- | ├ 🔴 crowdsecurity/endlessh-logs
- | ├ 🔴 baudneo/gotify-logs
- | ├ 🔴 crowdsecurity/iptables-logs
- | └ 🟢 crowdsecurity/nginx-logs (+23 ~2)
- ├ s02-enrich
- | ├ 🟢 crowdsecurity/dateparse-enrich (+2 ~2)
- | ├ 🟢 crowdsecurity/geoip-enrich (+13)
- | ├ 🟢 crowdsecurity/http-logs (+7)
- | ├ 🟢 my/whitelists (unchanged)
- | └ 🟢 crowdsecurity/whitelists (unchanged)
- ├-------- parser success 🟢
- ├ Scenarios
- ├ 🟢 crowdsecurity/http-crawl-non_statics
- └ 🟢 crowdsecurity/http-sensitive-files
- line: 70.39.90.4 - - [13/Feb/2025:01:26:32 +0000] "GET /alive.php HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
- ├ s00-raw
- | ├ 🔴 crowdsecurity/syslog-logs
- | └ 🟢 crowdsecurity/non-syslog (+5 ~8)
- ├ s01-parse
- | ├ 🔴 crowdsecurity/appsec-logs
- | ├ 🔴 crowdsecurity/auditd-logs
- | ├ 🔴 laurencejjones/dovecot-pam
- | ├ 🔴 crowdsecurity/dovecot-logs
- | ├ 🔴 crowdsecurity/endlessh-logs
- | ├ 🔴 baudneo/gotify-logs
- | ├ 🔴 crowdsecurity/iptables-logs
- | └ 🟢 crowdsecurity/nginx-logs (+23 ~2)
- ├ s02-enrich
- | ├ 🟢 crowdsecurity/dateparse-enrich (+2 ~2)
- | ├ 🟢 crowdsecurity/geoip-enrich (+13)
- | ├ 🟢 crowdsecurity/http-logs (+7)
- | ├ 🟢 my/whitelists (unchanged)
- | └ 🟢 crowdsecurity/whitelists (unchanged)
- ├-------- parser success 🟢
- ├ Scenarios
- └ 🟢 crowdsecurity/http-crawl-non_statics
- line: 80.94.92.181 - - [13/Feb/2025:01:33:27 +0000] "POST / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
- ├ s00-raw
- | ├ 🔴 crowdsecurity/syslog-logs
- | └ 🟢 crowdsecurity/non-syslog (+5 ~8)
- ├ s01-parse
- | ├ 🔴 crowdsecurity/appsec-logs
- | ├ 🔴 crowdsecurity/auditd-logs
- | ├ 🔴 laurencejjones/dovecot-pam
- | ├ 🔴 crowdsecurity/dovecot-logs
- | ├ 🔴 crowdsecurity/endlessh-logs
- | ├ 🔴 baudneo/gotify-logs
- | ├ 🔴 crowdsecurity/iptables-logs
- | └ 🟢 crowdsecurity/nginx-logs (+23 ~2)
- ├ s02-enrich
- | ├ 🟢 crowdsecurity/dateparse-enrich (+2 ~2)
- | ├ 🟢 crowdsecurity/geoip-enrich (+13)
- | ├ 🟢 crowdsecurity/http-logs (+6)
- | ├ 🟢 my/whitelists (unchanged)
- | └ 🟢 crowdsecurity/whitelists (unchanged)
- ├-------- parser success 🟢
- ├ Scenarios
- line: 198.235.24.224 - - [13/Feb/2025:02:39:36 +0000] "\x16\x03\x01\x00\xCA\x01\x00\x00\xC6\x03\x03\x0B\x1A*\xF8\x9D\xA2o\x94n\x81\xAE\xA2\xBD\xF9<\xFA\x85z\xBC\x07:\x94BM\x98MMp\xF8bf\xF0\x00\x00h\xCC\x14\xCC\x13\xC0/\xC0+\xC00\xC0,\xC0\x11\xC0\x07\xC0'\xC0#\xC0\x13\xC0\x09\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
- ├ s00-raw
- | ├ 🔴 crowdsecurity/syslog-logs
- | └ 🟢 crowdsecurity/non-syslog (+5 ~8)
- ├ s01-parse
- | ├ 🔴 crowdsecurity/appsec-logs
- | ├ 🔴 crowdsecurity/auditd-logs
- | ├ 🔴 laurencejjones/dovecot-pam
- | ├ 🔴 crowdsecurity/dovecot-logs
- | ├ 🔴 crowdsecurity/endlessh-logs
- | ├ 🔴 baudneo/gotify-logs
- | ├ 🔴 crowdsecurity/iptables-logs
- | └ 🟢 crowdsecurity/nginx-logs (+19 ~2)
- ├ s02-enrich
- | ├ 🟢 crowdsecurity/dateparse-enrich (+2 ~2)
- | ├ 🟢 crowdsecurity/geoip-enrich (+13)
- | ├ 🟢 crowdsecurity/http-logs (+7)
- | ├ 🟢 my/whitelists (unchanged)
- | └ 🟢 crowdsecurity/whitelists (unchanged)
- ├-------- parser success 🟢
- ├ Scenarios
- └ 🟢 crowdsecurity/http-probing
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement