{"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 608, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 961, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 258, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 621, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 485, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 76}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 114, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "admin", "failed_attempts": 21}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "root", "failed_attempts": 71}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 808, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 684, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "guest", "failed_attempts": 58}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 318, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 181, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 336, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 275, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 694, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "netops", "failed_attempts": 71}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 454, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 971, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 150, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 54}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 834, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 497, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 466, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 38}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 860, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "netops", "failed_attempts": 30}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 228, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "admin", "failed_attempts": 42}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 464, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 386, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "netops", "failed_attempts": 81}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 578, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 423, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "guest", "failed_attempts": 54}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 424, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 592, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 963, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "admin", "failed_attempts": 44}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 172, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "guest", "failed_attempts": 21}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 296, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 50}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 130, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 73}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 398, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 58}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 440, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 163, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 251, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 78}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 51}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "root", "failed_attempts": 90}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 205, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 389, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 288, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 910, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 334, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "admin", "failed_attempts": 27}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 426, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 387, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 758, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 103, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 98, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 26}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "guest", "failed_attempts": 17}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 23}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 792, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 535, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "root", "failed_attempts": 62}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 1000, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 440, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 432, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "guest", "failed_attempts": 74}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 110, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 131, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 64}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 438, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 134, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 244, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "admin", "failed_attempts": 32}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 525, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "guest", "failed_attempts": 38}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "root", "failed_attempts": 88}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 325, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 296, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "root", "failed_attempts": 82}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 856, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 268, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 46}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 186, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "failed_attempts": 245, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 16}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 623, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 669, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 291, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 130, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 263, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 514, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "admin", "failed_attempts": 48}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 63, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "root", "failed_attempts": 69}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "guest", "failed_attempts": 10}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 71}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 323, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 428, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 265, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "failed_attempts": 255, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 681, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 77}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 470, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 277, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "root", "failed_attempts": 48}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 304, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 237, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "netops", "failed_attempts": 69}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "admin", "failed_attempts": 19}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 473, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "admin", "failed_attempts": 43}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 585, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "failed_attempts": 417, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 80}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 173, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "admin", "failed_attempts": 46}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 490, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 66}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 354, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 168, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 84}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 996, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 30}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 43}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "admin", "failed_attempts": 62}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 724, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "root", "failed_attempts": 12}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 82}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 263, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 280, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "admin", "failed_attempts": 44}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 99, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "guest", "failed_attempts": 60}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 303, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 145, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 948, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 619, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "root", "failed_attempts": 26}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 380, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 421, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 662, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 180, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "netops", "failed_attempts": 88}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 410, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "admin", "failed_attempts": 13}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "netops", "failed_attempts": 25}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "guest", "failed_attempts": 89}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "guest", "failed_attempts": 63}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 65, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 205, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 406, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 567, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "admin", "failed_attempts": 84}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 414, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "netops", "failed_attempts": 91}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 456, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 13}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 115, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 33}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 287, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 426, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 582, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 351, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 59}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 70}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 259, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 271, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 369, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 235, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 396, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "root", "failed_attempts": 52}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "root", "failed_attempts": 42}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 429, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 528, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 84, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "root", "failed_attempts": 35}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 70}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 497, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 529, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 889, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "guest", "failed_attempts": 86}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 92, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 395, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 247, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 438, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 61, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 979, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "admin", "failed_attempts": 25}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 256, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 44}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 415, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 367, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "netops", "failed_attempts": 85}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 469, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 158, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 10}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "root", "failed_attempts": 32}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 485, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 69}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 222, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 396, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 57, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "netops", "failed_attempts": 81}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 135, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 92, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "root", "failed_attempts": 95}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 370, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 912, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "netops", "failed_attempts": 43}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 251, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 358, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 886, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 283, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "guest", "failed_attempts": 40}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 930, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 692, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "netops", "failed_attempts": 84}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 137, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 42}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "guest", "failed_attempts": 34}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 308, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 22}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "netops", "failed_attempts": 43}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 35}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 196, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 250, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 368, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "netops", "failed_attempts": 73}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "guest", "failed_attempts": 21}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 473, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 74, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "root", "failed_attempts": 28}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "admin", "failed_attempts": 59}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 48}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 697, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "guest", "failed_attempts": 61}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 396, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 238, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "root", "failed_attempts": 13}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 994, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 882, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 401, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "netops", "failed_attempts": 95}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "netops", "failed_attempts": 67}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "admin", "failed_attempts": 90}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "admin", "failed_attempts": 81}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 296, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 52}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 635, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "guest", "failed_attempts": 33}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 304, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 272, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 26}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "failed_attempts": 460, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "admin", "failed_attempts": 12}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 424, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 139, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 864, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "failed_attempts": 347, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "guest", "failed_attempts": 84}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 234, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "admin", "failed_attempts": 74}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 567, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 59}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 131, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 289, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "root", "failed_attempts": 44}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 882, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 888, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 78}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "guest", "failed_attempts": 57}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 511, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 436, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 236, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "root", "failed_attempts": 59}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 303, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 84}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 934, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 295, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "admin", "failed_attempts": 67}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 846, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 406, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 445, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "admin", "failed_attempts": 94}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 289, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 170, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 64}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 839, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 127, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 203, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 47}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "netops", "failed_attempts": 83}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 481, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 863, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 305, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 308, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 436, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "failed_attempts": 398, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 126, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 372, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 142, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 428, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 395, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 184, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 84, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 366, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 158, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "netops", "failed_attempts": 38}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "guest", "failed_attempts": 52}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 325, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 227, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 21}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 441, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 886, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 449, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 415, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 14}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 697, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "netops", "failed_attempts": 88}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 297, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 420, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "failed_attempts": 440, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "netops", "failed_attempts": 59}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "netops", "failed_attempts": 46}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "root", "failed_attempts": 29}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 949, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 340, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "guest", "failed_attempts": 57}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 229, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 231, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "admin", "failed_attempts": 46}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 56}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 294, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 26}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 705, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "root", "failed_attempts": 81}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 473, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 394, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 439, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "netops", "failed_attempts": 25}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 843, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 243, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 850, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "root", "failed_attempts": 13}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 214, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 746, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 592, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 26}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 233, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "guest", "failed_attempts": 46}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 172, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "root", "failed_attempts": 95}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "admin", "failed_attempts": 42}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "admin", "failed_attempts": 12}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 951, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 438, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 677, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 137, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "guest", "failed_attempts": 66}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 162, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 153, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 305, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 11}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "netops", "failed_attempts": 22}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 129, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 440, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 120, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 170, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 38}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 506, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 474, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 29}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "guest", "failed_attempts": 21}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 357, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 439, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 431, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 193, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "admin", "failed_attempts": 28}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "root", "failed_attempts": 39}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 961, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 911, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 422, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 240, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 152, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 882, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 640, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 540, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 129, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 324, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "root", "failed_attempts": 78}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 212, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 71}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 29}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 90}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 241, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 252, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 412, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 375, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "netops", "failed_attempts": 32}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 544, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 427, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 805, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 884, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 526, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 20}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "netops", "failed_attempts": 56}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 715, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 345, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 113, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 120, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "guest", "failed_attempts": 80}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 255, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 216, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 35}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "guest", "failed_attempts": 68}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "failed_attempts": 319, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 275, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 28}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 321, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 353, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 133, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 730, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "guest", "failed_attempts": 42}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 242, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 958, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 346, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 378, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 211, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 672, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 851, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 222, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 306, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 131, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 99}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 281, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 127, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 682, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 248, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 288, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 458, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 57}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 726, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "admin", "failed_attempts": 53}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 85, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 185, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 255, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 411, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 949, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 771, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "netops", "failed_attempts": 92}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 203, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 798, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 334, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 266, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 329, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 187, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 742, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 406, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 264, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 286, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 288, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 25}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "guest", "failed_attempts": 34}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 310, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 537, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 109, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 902, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "guest", "failed_attempts": 42}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 67}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "admin", "failed_attempts": 62}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "netops", "failed_attempts": 19}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 340, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 205, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 750, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 293, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 101, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "admin", "failed_attempts": 56}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 293, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "guest", "failed_attempts": 47}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 247, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 770, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 994, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 123, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "netops", "failed_attempts": 34}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 230, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 49}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "root", "failed_attempts": 89}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 126, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 178, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 654, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 331, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 342, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 16}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 911, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "root", "failed_attempts": 40}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 348, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 498, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 763, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 923, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "netops", "failed_attempts": 41}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 228, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 185, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 98, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 233, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 320, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 253, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 375, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "root", "failed_attempts": 71}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 339, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "root", "failed_attempts": 51}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 339, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 695, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 789, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 11}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 153, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "admin", "failed_attempts": 57}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 125, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 57, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 307, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 651, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 919, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 501, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 110, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 85, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 348, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 269, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 802, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 214, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 31}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "guest", "failed_attempts": 42}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 217, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 551, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 920, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 300, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 807, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "admin", "failed_attempts": 38}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 122, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 208, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "admin", "failed_attempts": 92}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 950, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 53, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 205, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 349, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 765, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 797, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 448, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 481, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 931, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 628, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 276, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 82}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 694, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 332, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "guest", "failed_attempts": 69}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 373, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 160, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 741, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 532, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "admin", "failed_attempts": 96}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 60}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 78}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 576, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 724, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 262, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 313, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "root", "failed_attempts": 34}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 24}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 749, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 797, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 181, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 598, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "failed_attempts": 435, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 230, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "admin", "failed_attempts": 59}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 831, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 831, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 620, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 889, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 203, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "admin", "failed_attempts": 33}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 367, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 367, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 896, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 173, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 275, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "root", "failed_attempts": 73}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 379, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "netops", "failed_attempts": 40}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 778, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 393, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 324, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 185, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 195, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "admin", "failed_attempts": 84}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 860, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 842, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "netops", "failed_attempts": 16}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 16}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 212, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 490, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 844, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 21}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 172, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 394, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 91}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 806, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "netops", "failed_attempts": 47}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 327, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 94}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 645, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 938, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 167, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 976, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 30}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 33}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "failed_attempts": 214, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 323, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 270, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 39}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 78}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 50}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 137, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "netops", "failed_attempts": 12}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 455, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "guest", "failed_attempts": 95}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 78}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 428, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 493, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 342, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 564, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 611, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 982, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 877, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 74, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "admin", "failed_attempts": 53}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 239, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "admin", "failed_attempts": 37}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 152, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "guest", "failed_attempts": 14}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 95, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 807, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 73}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 24}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 68}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 428, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 800, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 916, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 26}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 21}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 493, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "guest", "failed_attempts": 70}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 15}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 429, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 314, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 497, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "guest", "failed_attempts": 48}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 447, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 56, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 870, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 75}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "admin", "failed_attempts": 64}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 351, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 156, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 296, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 269, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 304, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 59}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "user": "netops", "failed_attempts": 50}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 329, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 696, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "netops", "failed_attempts": 87}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 166, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 485, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 408, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "root", "failed_attempts": 34}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 708, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 528, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 826, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 92}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 139, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 36}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "guest", "failed_attempts": 32}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "root", "failed_attempts": 28}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 55}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 202, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 270, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 446, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 267, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "netops", "failed_attempts": 36}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "root", "failed_attempts": 44}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "root", "failed_attempts": 30}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 416, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "root", "failed_attempts": 78}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 833, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "netops", "failed_attempts": 35}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 859, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 61, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 877, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "guest", "failed_attempts": 42}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 80}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 845, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 908, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "netops", "failed_attempts": 82}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "root", "failed_attempts": 87}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 409, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 675, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 890, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "netops", "failed_attempts": 70}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "failed_attempts": 175, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "failed_attempts": 62, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "admin", "failed_attempts": 80}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "root", "failed_attempts": 68}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 830, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 125, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 913, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 460, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 546, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "root", "failed_attempts": 24}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 110, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "admin", "failed_attempts": 47}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 291, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "netops", "failed_attempts": 58}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 410, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 88}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 681, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 178, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 821, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 402, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 86, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 51, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 654, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 712, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 16}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 497, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 19}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 348, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 421, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "guest", "failed_attempts": 62}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 345, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 93, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "netops", "failed_attempts": 78}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 288, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 129, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "netops", "failed_attempts": 62}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "guest", "failed_attempts": 80}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 100, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 156, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 180, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 955, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 37}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 85}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 96, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 140, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 41}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 139, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 54, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "admin", "failed_attempts": 53}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 45}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 108, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 118, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 570, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 994, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 121, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "guest", "failed_attempts": 45}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 421, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "admin", "failed_attempts": 74}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 777, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 127, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "admin", "failed_attempts": 24}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 265, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 88, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 58, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 962, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 56}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 211, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "guest", "failed_attempts": 25}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "netops", "failed_attempts": 62}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 620, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 415, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 461, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 282, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "netops", "failed_attempts": 41}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 472, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "failed_attempts": 193, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 859, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "guest", "failed_attempts": 80}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 32}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 10}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "failed_attempts": 432, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 30}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 66}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 227, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 136, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 320, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 67}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 677, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "netops", "failed_attempts": 89}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 350, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Vlan99", "failed_attempts": 498, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 280, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 77}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 137, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "root", "failed_attempts": 72}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "admin", "failed_attempts": 86}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 257, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "user": "admin", "failed_attempts": 52}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 12}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 55}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "admin", "failed_attempts": 92}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "root", "failed_attempts": 38}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 983, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 738, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 160, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 701, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 240, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 187, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "admin", "failed_attempts": 85}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 330, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 313, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 338, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "admin", "failed_attempts": 90}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 165, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 937, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 927, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 335, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "failed_attempts": 103, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 589, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 301, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "failed_attempts": 394, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 367, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 158, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "user": "root", "failed_attempts": 30}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "monitor", "failed_attempts": 501, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 223, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/1", "user": "root", "failed_attempts": 43}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 107, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "monitor", "failed_attempts": 356, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 790, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 837, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 130, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 380, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "guest", "failed_attempts": 100}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 388, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 82}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "netops", "failed_attempts": 72}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "netops", "failed_attempts": 28}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Loopback0", "user": "root", "failed_attempts": 94}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "failed_attempts": 404, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 122, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "public", "failed_attempts": 543, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/2", "failed_attempts": 252, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 222, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "failed_attempts": 165, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 169, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 50, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "user": "admin", "failed_attempts": 74}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "Loopback0", "user": "guest", "failed_attempts": 26}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "Loopback0", "failed_attempts": 352, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/2", "user": "root", "failed_attempts": 45}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 678, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 28}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 83}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "user": "netops", "failed_attempts": 22}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 353, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "Vlan99", "user": "netops", "failed_attempts": 69}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "private", "failed_attempts": 971, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 206, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 626, "source_ip": "10.10.10.5"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "root", "failed_attempts": 17}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/2", "user": "guest", "failed_attempts": 99}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "snmp_community": "public", "failed_attempts": 987, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "admin", "failed_attempts": 72}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 355, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 59, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 35}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 571, "source_ip": "203.0.113.45"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 348, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/1", "failed_attempts": 454, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "user": "guest", "failed_attempts": 71}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/0", "failed_attempts": 436, "source_ip": "198.51.100.77"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "CORE-R1", "interface": "GigabitEthernet0/0", "failed_attempts": 385, "source_ip": "10.10.10.5"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "user": "admin", "failed_attempts": 34}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "public", "failed_attempts": 724, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 356, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "GigabitEthernet0/0", "failed_attempts": 130, "source_ip": "203.0.113.45"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "guest", "failed_attempts": 64}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "private", "failed_attempts": 772, "source_ip": "192.0.2.88"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium", "description": "Repeated authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "interface": "GigabitEthernet0/1", "user": "admin", "failed_attempts": 45}], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "CORE-R1", "snmp_community": "private", "failed_attempts": 136, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88", "description": "Multiple failed SSH login attempts detected from a single source."}, "devices": [{"name": "EDGE-FW1", "interface": "Vlan99", "failed_attempts": 244, "source_ip": "192.0.2.88"}], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 120 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incidents and output ONLY CLI FIX COMMANDS. Do not explain.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77", "description": "Multiple SNMP authentication failures detected."}, "devices": [{"name": "BRANCH-RTR1", "snmp_community": "monitor", "failed_attempts": 637, "source_ip": "198.51.100.77"}], "cli_fix": ["no snmp-server community monitor", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]}