Hi all,
I’ve been through the provided vendor rules in Logpoint and they are not useful. Does anyone have any rules that they can share that detect the attacks mentioned in the OWASP top 10?
Thank you
Hi all,
I’ve been through the provided vendor rules in Logpoint and they are not useful. Does anyone have any rules that they can share that detect the attacks mentioned in the OWASP top 10?
Thank you
Hello Muhammad,
Do you have WAF log sources? It will be very easy, if you have WAF product in our environment
Hi Kimil,
We do have a WAF but we want to detect it on IIS.
Thanks
Hello Muhammad,
Thank you for joining the Community !
All Alert Rules provided by LogPoint are available on our Documentation portal: https://docs.logpoint.com/docs/alert-rules/en/latest/MITRE.html
If you search (Ctrl-F) for “Webserver” you will find Alert Rules using Webserver logs, like these for examples:
While the LogPoint SIEM will not replace a full-fledged Web Application Firewall, it still provides a good first layer of detection thanks to predefined or custom Alert Rules.
Hope it helps !
Thanks,
Adrien
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.