Forcepoint Secure Web Gateway unusual spike found in web category urls
Set up the forcepoint-secure-web-gateway integration.
Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel,
n'hésitez pas à nous contacter.
Goal
Identify an unusual spike in request for URLs within a {{@webcategories}}.
Strategy
This rule analyzes Forcepoint SWG logs to detect an abnormal increase in requests for URLs within a specific web category.
Triage and Response
- Analyze the Forcepoint SWG logs and identify the users and user groups associated with spike in request for web category
{{@webcategories}}
URLs. - Check the web reputation of the URLs being accessed within the flagged category. Ensure that no high-risk URLs or known malicious destinations are being requested.
- Examine any correlated activities that could be linked to the spike, such as file uploads, downloads, or data requests that may raise security concerns (such as matching DLP patterns or confidential data uploads).
- Review actions taken by Forcepoint SWG, and block the web category or specific URLs associated with suspicious activity if they have not already been blocked.
- Notify the users about the suspicious activity and educate them on safe browsing practices.