-
Notifications
You must be signed in to change notification settings - Fork 195
Description
Hello CrowdSec team,
Following a discussion on Discord about this, it would be interesting to have a Crowdsec Collection for RabbitMQ.
RabbitMQ should be protected from : Unauthorized login attempts ; Brute-force attacks ; Abuse of weak/default credentials.
A dedicated collection would help detect malicious activity and strengthen security around messaging infrastructures.
I have also started working on the collection on my own, attempting to create a parser and scenarios. However, I currently do not have anything functional yet. I believe an officially supported or community-backed implementation would be more robust and beneficial.
Here is a redacted sample of logs from my RabbitMQ server. (/var/log/rabbitmq/[email protected])
Anything that does not originate from Class B (172.16.0.0/12) private addresses is junk traffic and yes, it's normal for me to expose this service because even though it only works locally at the moment, that will change in the future.
rabbitmq-sample.log
Thanks for considering this request — I believe it would be a great addition to the Hub!