Skip to content

Feature Request: Add a RabbitMQ Collection to CrowdSec Hub #1578

@GautDlpr

Description

@GautDlpr

Hello CrowdSec team,
Following a discussion on Discord about this, it would be interesting to have a Crowdsec Collection for RabbitMQ.

RabbitMQ should be protected from : Unauthorized login attempts ; Brute-force attacks ; Abuse of weak/default credentials.

A dedicated collection would help detect malicious activity and strengthen security around messaging infrastructures.

I have also started working on the collection on my own, attempting to create a parser and scenarios. However, I currently do not have anything functional yet. I believe an officially supported or community-backed implementation would be more robust and beneficial.

Here is a redacted sample of logs from my RabbitMQ server. (/var/log/rabbitmq/[email protected])
Anything that does not originate from Class B (172.16.0.0/12) private addresses is junk traffic and yes, it's normal for me to expose this service because even though it only works locally at the moment, that will change in the future.
rabbitmq-sample.log

Thanks for considering this request — I believe it would be a great addition to the Hub!

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions