Protection Alert Use Cases
Traceable's advanced alert conditions allow you to compare specific attributes, such as threat type and severity level, against expected values or against one another, rather than relying on simple event triggers alone. The following table describes the different available attributes, event type, and its description:
Threat Actor
Create
Update
Provides visibility into threat actors associated with suspicious or malicious activity.
API Protection
Update
Provides visibility into API protection policies and their enforcement.
Custom Signature
Create
Update
Delete
Provides visibility into custom signature policies for organization-specific threats and attack patterns.
Data Loss Prevention
Create
Update
Delete
Provides visibility into sensitive data exposure and prevention activities.
Exclusions
Create
Update
Delete
Provides visibility into policy and detection rule exclusions.
Enumeration
Create
Update
Delete
Provides visibility into enumeration attempts targeting resources, accounts, or identifiers.
Malicious Sources
Create
Update
Delete
Provides visibility into traffic originating from known malicious sources.
Rate Limiting
Create
Update
Delete
Provides visibility into rate-limiting policies and enforcement actions.
Security Event – Rule Triggers
Create
Provides visibility into security events generated by policy and rule violations.
Threat Auto Blocking
Update
Provides visibility into automated threat-blocking actions.
Threat Scoring Configuration
Update
Provides visibility into threat-scoring criteria and risk assessments.
Web Application Firewall
Update
Provides visibility into web application firewall protections and events.
Advanced alert configuration sample scenarios
The following sample scenarios demonstrate how to configure condition groups and conditions for Protection alerts for the Update Event type:
Last updated
Was this helpful?

