Files
Docker-Compose/Security_Containers/crowdsec/geoip-allow.yaml
T

7 lines
223 B
YAML

name: crowdsecurity/geoip-allow-us-de
description: "Block all countries except US and Germany"
filter: "evt.Enriched.IsoCode != 'US' && evt.Enriched.IsoCode != 'DE'"
blackhole: 1m
labels:
type: geo_block
remediation: true