secubox-openwrt/package/secubox/secubox-app-crowdsec-custom/files/parsers/s01-parse
CyberMind-FR f4b9c910c5 feat(mitmproxy): Add WAN protection mode for incoming traffic inspection
Add WAF-like functionality to mitmproxy for protecting services exposed
to the internet. Incoming WAN traffic is redirected through mitmproxy
for threat detection before reaching backend services.

Features:
- WAN protection mode with nftables rules for incoming traffic
- Enhanced bot scanner detection with 50+ scanner signatures
- Behavioral detection for config/admin/backup/shell hunting
- CrowdSec integration with new scenarios for bot scanners
- LuCI interface for WAN protection configuration
- DPI mirror mode support (secondary feature)

New CrowdSec scenarios:
- secubox/mitmproxy-botscan: Detect automated reconnaissance
- secubox/mitmproxy-shell-hunter: Detect shell/backdoor hunting
- secubox/mitmproxy-config-hunter: Detect credential file hunting
- secubox/mitmproxy-suspicious-ua: Detect suspicious user agents

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-02-02 10:07:40 +01:00
..
secubox-gitea.yaml feat(crowdsec+haproxy): Dashboard refactor, custom parsers & scenarios 2026-01-27 11:16:17 +01:00
secubox-haproxy.yaml fix(crowdsec): Fix parsers and acquisition for v1.7.6 compatibility 2026-01-27 12:08:03 +01:00
secubox-luci-auth.yaml feat(crowdsec): Add custom CrowdSec scenarios package for SecuBox 2026-01-22 14:50:36 +01:00
secubox-mitmproxy.yaml feat(mitmproxy): Add WAN protection mode for incoming traffic inspection 2026-02-02 10:07:40 +01:00
secubox-streamlit.yaml fix(crowdsec): Fix parsers and acquisition for v1.7.6 compatibility 2026-01-27 12:08:03 +01:00
secubox-webapp.yaml feat(crowdsec+haproxy): Dashboard refactor, custom parsers & scenarios 2026-01-27 11:16:17 +01:00