Wazuh - Large Number of Web errors from an IP

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies instances where Wazuh logged over 400 '403' Web Errors from one IP Address. To onboard Wazuh data into Sentinel please view: https://documentation.wazuh.com/current/cloud-security/azure/index.html

Attribute Value
Type Analytic Rule
Solution Standalone Content
ID 2790795b-7dba-483e-853f-44aa0bc9c985
Severity Low
Kind Scheduled
Tactics CredentialAccess
Techniques T1110
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules