This Story receives a Panther alert and checks if it is an SSH brute force attack, enriching it via Panther and AbuseIPDB. Then, it blocks it in AWS ACLs, creates a Jira ticket, and sends a Slack message to a channel.
Eoin Magner
How it works
Import this story to your tenant, from where you can adapt it to meet your unique needs.
Import