iboss multiple soft blocked requests detected

This rule is part of a beta feature. To learn more, contact Support.
Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detects multiple soft block events from a user, which may indicate attempts to access restricted or risky content that violates security policies.

Strategy

Monitor soft-blocked web requests to identify patterns of repeated access attempts to disallowed or potentially harmful content.

Triage and Response

  1. Identify the user {{@usr.name}} and the device {{@computerName}} generating the soft-blocked requests.
  2. Review the client IP address {{@network.client.ip}} to validate network origin and assess for unusual activity.
  3. Determine whether the accessed content is harmful, miscategorized, or being intentionally bypassed.