{"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "198.51.100.77"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 198.51.100.77", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "192.0.2.88"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 192.0.2.88", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "EDGE-FW1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "BRANCH-RTR1", "severity": "high", "source_ip": "10.10.10.5"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 10.10.10.5", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "EDGE-FW1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "CORE-R1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community public", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "ssh_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SSH brute force detected", "device": "CORE-R1", "severity": "high", "source_ip": "203.0.113.45"}, "allowed_actions": ["vt_access_class", "login_block"], "disallowed_actions": ["snmp_config", "console_config", "acl_deletion"], "cli_fix": ["ip access-list standard MGMT_SSH", "deny host 203.0.113.45", "permit any", "exit", "line vty 0 4", "access-class MGMT_SSH in", "login block-for 60 attempts 3 within 60"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "BRANCH-RTR1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "BRANCH-RTR1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "snmp_bruteforce", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "SNMP brute force detected", "device": "EDGE-FW1", "severity": "high"}, "allowed_actions": ["snmp_v3_migration"], "disallowed_actions": ["vty_config", "login_block", "acl_config"], "cli_fix": ["no snmp-server community private", "snmp-server group SECURE v3 priv", "snmp-server user monitor SECURE v3 auth sha AUTHKEY priv aes 128 PRIVKEY"]} {"incident_type": "failed_login_attempts", "instruction": "Analyze management-plane security incident and generate Cisco IOS CLI fix commands.", "wazuh_alert": {"rule": "Excessive failed login attempts", "device": "CORE-R1", "severity": "medium"}, "allowed_actions": ["login_block"], "disallowed_actions": ["snmp_config", "acl_config", "vty_access_class"], "cli_fix": ["login block-for 60 attempts 3 within 60", "login on-failure log", "login on-success log"]}