Credential Stuffing Detection
Credential stuffing detection that finds what hides under per-IP thresholds. Success-rate inversion, low-and-slow campaigns, and ATO signals in SPL and KQL.
5 articles
Credential stuffing detection that finds what hides under per-IP thresholds. Success-rate inversion, low-and-slow campaigns, and ATO signals in SPL and KQL.
An OAuth misconfiguration defensive review — redirect_uri validation, PKCE and state, detecting off-allowlist redirects and token anomalies, aligned to RFC 9700.
Detect GraphQL authorization mistakes — BOLA argument manipulation, introspection exposure, and query-level-only checks, with Sigma rules and hardening.
Broken access control testing for defenders — detect IDOR and BOLA from authorization-failure telemetry with Sigma and SPL rules, plus deny-by-default hardening.
JWT misconfiguration detection and defense — alg:none, RS256-to-HS256 confusion, and kid injection, with header-logging detection, Sigma rules, and MITRE mapping.