54c5c17aa3
* [Rule tuning & Addition] SSH Bruteforce * Update rules/linux/credential_access_potential_linux_ssh_bruteforce_internal.toml Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com> * Update rules/linux/credential_access_potential_linux_ssh_bruteforce_external.toml Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com> * Update rules/linux/credential_access_potential_linux_ssh_bruteforce_external.toml Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com> * Update rules/linux/credential_access_potential_linux_ssh_bruteforce_external.toml Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> * Update rules/linux/credential_access_potential_linux_ssh_bruteforce_internal.toml Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> * fixed rule_id change, added additional cidr match * added host.os.type==linux * Update credential_access_potential_linux_ssh_bruteforce_internal.toml * Formatting style change * Update rules/linux/credential_access_potential_linux_ssh_bruteforce_external.toml Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> * Update rules/linux/credential_access_potential_linux_ssh_bruteforce_external.toml Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> * Added related rules suggestion * Added related rule suggestion * added additional internal ip ranges * added additional internal ip ranges --------- Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com> Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com> Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>