Add Security_Containers/crowdsec/postoverflows/s01-whitelist/geoip-allow.yaml
This commit is contained in:
@@ -0,0 +1,7 @@
|
|||||||
|
name: crowdsecurity/geoip-allow-us-de
|
||||||
|
description: "Block all countries except US and Germany"
|
||||||
|
filter: "evt.Enriched.IsoCode != 'US' && evt.Enriched.IsoCode != 'DE'"
|
||||||
|
blackhole: 1m
|
||||||
|
labels:
|
||||||
|
type: geo_block
|
||||||
|
remediation: true
|
||||||
Reference in New Issue
Block a user