Forcepoint Secure Web Gateway threat indicator detected
Set up the forcepoint-secure-web-gateway integration.
Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel,
n'hésitez pas à nous contacter.
Goal
Identify that a threat indicator was detected within Forcepoint Secure Web Gateway.
Strategy
This rule analyzes Forcepoint SWG logs to identify a detected threat indicator.
Triage and Response
- Analyze the Forcepoint SWG logs and identify the user
{{@usr.name}}
associated with the occurrences of flagged threat indicator. - Review activities, accessed URLs, and files associated with the flagged threat indicators to understand the nature of the threat indicator.
- Assess web categories and reputation scores of accessed URLs.
- Examine patterns like DLP pattern or keyword to identify sensitive or regulated data involved in the flagged actions.
- Quarantine flagged files or data uploads if they contain sensitive information.
- Block further access to flagged URLs or applications if not already restricted.
- Suspend or reset the user’s account credentials if compromise is suspected.