diff --git a/roles/crowdsec/tasks/conf.yml b/roles/crowdsec/tasks/conf.yml index 3af2bf8..3703198 100644 --- a/roles/crowdsec/tasks/conf.yml +++ b/roles/crowdsec/tasks/conf.yml @@ -6,7 +6,7 @@ - config.yaml - acquis.yaml - simulation.yaml - - profile.yaml + - profiles.yaml - parsers/s02-enrich/trusted_ip.yaml notify: reload crowdsec tags: crowdsec diff --git a/roles/crowdsec/templates/profiles.yaml.j2 b/roles/crowdsec/templates/profiles.yaml.j2 new file mode 100644 index 0000000..2d58e39 --- /dev/null +++ b/roles/crowdsec/templates/profiles.yaml.j2 @@ -0,0 +1,7 @@ +name: default_ip_remediation +filters: + - Alert.Remediation == true && Alert.GetScope() == "Ip" +decisions: + - type: ban + duration: {{ crowdsec_ban_duration }} +on_success: break diff --git a/roles/squid/files/acl/software_various.domains b/roles/squid/files/acl/software_various.domains index 7caea0d..4ebb5c3 100644 --- a/roles/squid/files/acl/software_various.domains +++ b/roles/squid/files/acl/software_various.domains @@ -346,7 +346,7 @@ store.itophub.io # Crowdsec crowdsec-statics-assets.s3-eu-west-1.amazonaws.com -api.crowdsec.com +api.crowdsec.net www.cloudflare.com # Metabase