๐‘๐š๐ญ๐ž ๐‹๐ข๐ฆ๐ข๐ญ๐ข๐ง๐  ๐…๐ž๐š๐ญ๐ฎ๐ซ๐ž ๐Ÿ๐จ๐ซ ๐€๐ณ๐ฎ๐ซ๐ž ๐–๐€๐… ๐จ๐ง ๐€๐ฉ๐ฉ๐ฅ๐ข๐œ๐š๐ญ๐ข๐จ๐ง ๐†๐š๐ญ๐ž๐ฐ๐š๐ฒ ๐ง๐จ๐ฐ ๐ข๐ง ๐๐ซ๐ž๐ฏ๐ข๐ž๐ฐ

This feature allows you to define custom rules to limit the number of requests from different sources, such as IP addresses, geographies, or user sessions.

https://techcommunity.microsoft.com/t5/azure-network-security-blog/rate-limiting-feature-for-azure-waf-on-application-gateway-now/ba-p/3934957

#azure #microsoft #azuresecurity #waf #webapplicationgateway #appsecurity #azureapplicationgateway #appsec #webapplicationfirewall #firewall #ddos #azurewaf #cybersecurity #cloud #cloudnative #cloudsecurity #soc

Rate Limiting Feature for Azure WAF on Application Gateway now in Preview.

Rate Limiting Feature on Application Gateway WAF is now in Public Preview.

TECHCOMMUNITY.MICROSOFT.COM

๐—”๐˜‡๐˜‚๐—ฟ๐—ฒ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ก๐—ฒ๐˜„๐˜€: ๐—”๐˜‡๐˜‚๐—ฟ๐—ฒ ๐——๐——๐—ผ๐—ฆ ๐—ฆ๐—ฒ๐—ป๐˜๐—ถ๐—ป๐—ฒ๐—น ๐—ฆ๐—ผ๐—น๐˜‚๐˜๐—ถ๐—ผ๐—ป ๐—ฎ๐—ป๐—ฑ ๐—ช๐—”๐—™ ๐—ฃ๐—น๐—ฎ๐˜†๐—ฏ๐—ผ๐—ผ๐—ธ ๐—œ๐—ป๐˜๐—ฒ๐—ด๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป

Learn how to how to integrate the Azure DDoS Sentinel Solution with the Azure WAF Playbook to enable a powerful automated detection and response system.

With this integration, the Azure DDoS Sentinel Solution and the WAF Playbook work together to prevent attacks with the steps described below:

1๏ธโƒฃDuring the first stage of a multi-vector attack campaign, initiated by a malicious actor, the DDoS attack floods the customerโ€™s application, creating chaos and serving as a diversion for the subsequent attack.

2๏ธโƒฃUpon identifying the DDoS attack, Azure DDoS protection mitigates the attack and generates logs that are transmitted to Microsoft Sentinel.

3๏ธโƒฃMicrosoft Sentinel extracts the source IP addresses of the attackers from the logs and triggers the WAF Playbook.

4๏ธโƒฃThe WAF Playbook adds the attack IP addresses to a custom WAF rule with a block action. Azure WAF becomes ready to mitigate the forthcoming stages of the adversary's attack cycle.

5๏ธโƒฃHaving employed the DDoS attack as a smokescreen, the adversary now attempts to breach the application to take the sensitive data.

6๏ธโƒฃAzure WAF acts by blocking access from the source IP addresses of the attacker, thereby preventing them from reaching the data.

https://techcommunity.microsoft.com/t5/azure-network-security-blog/enhancing-your-azure-security-azure-ddos-sentinel-solution-and/ba-p/3913420

#azure #azuresecurity #azurenetworksecurity #ddos #azureddos #waf #azurewaf #sentinel #microsoftsentinel #microsoft #soc #automation #soar #siem #playbook #cybersecurity #microsoft #microsoftsecurity #cloudsecurity

Enhancing Your Azure Security: Azure DDoS Sentinel Solution and WAF Playbook Integration

In this blog, we explore the integration of the Azure DDoS Sentinel Solution with the WAF Playbook. DDoS attacks often serve as a cover for concealing more..

TECHCOMMUNITY.MICROSOFT.COM

๐ƒ๐ž๐Ÿ๐ž๐ง๐๐ž๐ซ ๐Ÿ๐จ๐ซ ๐€๐๐ˆ๐ฌ ๐๐ž๐ญ๐ญ๐ž๐ซ ๐“๐จ๐ ๐ž๐ญ๐ก๐ž๐ซ ๐ฐ๐ข๐ญ๐ก ๐€๐ณ๐ฎ๐ซ๐ž ๐–๐ž๐› ๐€๐ฉ๐ฉ๐ฅ๐ข๐œ๐š๐ญ๐ข๐จ๐ง ๐…๐ข๐ซ๐ž๐ฐ๐š๐ฅ๐ฅ ๐š๐ง๐ ๐€๐ณ๐ฎ๐ซ๐ž ๐€๐๐ˆ ๐Œ๐š๐ง๐š๐ ๐ž๐ฆ๐ž๐ง๐ญ

The synergy of Microsoft Defender for APIs, Azure WAF, and Azure API Management forms a strong defense against API threats.

https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/defender-for-apis-better-together-with-azure-web-application/ba-p/3907308

โœ”๏ธThe WAF on Application Gateway checks the request against WAF rules. If the request is valid, then it will proceed.

โœ”๏ธApplication Gateway directs the request to APIM.

โœ”๏ธAPIM accepts and properly maps the requests.

โœ”๏ธDefender for APIs inspects API endpoints and gives insight on whether the API is properly authenticated, inactive, and externally facing.

โœ”๏ธDefender for APIs monitors the traffic going to and from APIM to classify sensitive data and alert on exploits and anomalies.

๐ƒ๐ž๐Ÿ๐ž๐ง๐๐ž๐ซ ๐Ÿ๐จ๐ซ ๐€๐๐ˆ๐ฌ

Defender for APIs provides visibility into crucial APIs. It facilitates a deep dive into your API security, allowing prioritization of vulnerabilities and quick detection of active threats. Key features include a consolidated view of managed APIs with security insights on external, inactive, or unauthenticated APIs, data classifications of sensitive data in API interactions, and machine learning-driven detection of API threats in alignment with the OWASP API Top 10.

๐€๐ณ๐ฎ๐ซ๐ž ๐€๐๐ˆ ๐Œ๐š๐ง๐š๐ ๐ž๐ฆ๐ž๐ง๐ญ

Azure API Management caters to the entire API lifecycle. APIM includes an API gateway, management platform, and developer portal. The gateway manages requests, ensures authentication, transforms requests and responses, caches responses, enforces usage caps, emits logs, and more.

๐€๐ณ๐ฎ๐ซ๐ž ๐–๐ž๐› ๐€๐ฉ๐ฉ๐ฅ๐ข๐œ๐š๐ญ๐ข๐จ๐ง ๐…๐ข๐ซ๐ž๐ฐ๐š๐ฅ๐ฅ

Azure WAF provides a centralized defense against web and API vulnerabilities like SQL injections and cross-site scripting attacks. With its rapid virtual patching, Azure WAF offers quick threat mitigation without needing to individually secure every web application.

#microsoft #azure #azurewaf #waf #api #defenderapi #sqlinjection #apim #apimanagement #defenderforapi #defenderforcloud #defender #cloud #cloudsecurity #cloudnative #soc #owasp #apithreats #cybersecurity

Defender for APIs Better Together with Azure Web Application Firewall and Azure API Management

This article discusses the interplay between Defender for APIs, Azure Web Application Firewall (Azure WAF), and Azure API Management (APIM). Learn about their..

TECHCOMMUNITY.MICROSOFT.COM

๐Ÿ” ๐€๐ณ๐ฎ๐ซ๐ž ๐–๐€๐… โ€“ ๐Œ๐š๐ฌ๐ค๐ข๐ง๐  ๐’๐ž๐ง๐ฌ๐ข๐ญ๐ข๐ฏ๐ž ๐ƒ๐š๐ญ๐š

WAF rules can thwart malicious requests containing personally identifiable info (PII). Azure WAF log scrubbing tool ensures data security. ๐Ÿ›ก๏ธ Safeguard your logs by removing sensitive data using custom rules.

Check out our latest blog where we dive into the log scrubbing feature and explore real examples. Discover how to strengthen your web app security today!

https://techcommunity.microsoft.com/t5/azure-network-security-blog/azure-waf-masking-sensitive-data/ba-p/3905356

#AzureWAF #WebAppSecurity #Azure #waf #scrubbing #log #sentinel #siem #soar #pii #cloud #cloudsecurity #soc #cybersecurity #loganalytics

Azure WAF โ€“ Masking Sensitive Data

Learn how to use Azure WAF's log scrubbing tool to mask sensitive data from your WAF logs. Mitigate against PII and sensitive data leakage from potential..

TECHCOMMUNITY.MICROSOFT.COM

๐ˆ๐ง๐ญ๐ซ๐จ๐๐ฎ๐œ๐ข๐ง๐  ๐€๐ณ๐ฎ๐ซ๐ž ๐–๐ž๐› ๐€๐ฉ๐ฉ๐ฅ๐ข๐œ๐š๐ญ๐ข๐จ๐ง ๐…๐ข๐ซ๐ž๐ฐ๐š๐ฅ๐ฅ'๐ฌ ๐’๐ž๐ง๐ฌ๐ข๐ญ๐ข๐ฏ๐ž ๐ƒ๐š๐ญ๐š ๐๐ซ๐จ๐ญ๐ž๐œ๐ญ๐ข๐จ๐ง (๐๐ซ๐ž๐ฏ๐ข๐ž๐ฐ)!

Data privacy is paramount, and Azure Web Application Firewall (WAF) has taken a step forward with Log Scrubbing.

This preview feature allows you to remove sensitive information from WAF logs, ensuring enhanced privacy and compliance. Safeguard your data with Azure WAF's Log Scrubbing.

Learn more:

https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/waf-sensitive-data-protection

https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/waf-sensitive-data-protection-configure?tabs=browser

#DataPrivacy #AzureWAF #waf #logging #data #privacy #scrubbing #logscrubbing #azure #compliance #cloudnative #appsecurity #webapp #cybersecurity #microsoftsecurity #microsoft

Azure Web Application Firewall Sensitive Data Protection

Learn about Azure Web Application Firewall Sensitive Data Protection.

Azure WAF guided investigation Notebook using Microsoft Sentinel for automated false positive tuning

Azure Web Application Firewall (Azure WAF) provides core protection for your web applications against exploits and vulnerabilities. It protects against OWASP Top 10 attacks, bot attacks, application-level distributed denial of service (DDoS) attacks, and other web attacks.

https://azure.microsoft.com/de-de/blog/azure-waf-guided-investigation-notebook-using-microsoft-sentinel-for-automated-false-positive-tuning/

#Microsoft #Azure #AzureFirewall #AzureWAF

Azure WAF guided investigation Notebook using Microsoft Sentinel for automated false positive tuning | Azure-Blog und -Updates| Microsoft Azure

Azure Web Application Firewall (Azure WAF) provides centralized protection of your web applications from exploits and vulnerabilities.

Azure Networking has released an update which includes a feature that blocks domain fronting behavior on newly created customer resources, as well as feature enhancements to Azure Web Application Firewall (WAF). https://techcommunity.microsoft.com/t5/itops-talk-blog/what-s-new-in-azure-networking-january-2023-edition/ba-p/3724304 #AzureNetworking #DomainFronting #AzureWAF
What's New in Azure Networking โ€“ January 2023 edition

What's New in Azure Networking โ€“ January 2023   Hello Folks,     As @Michael mentioned last month Azure Networking is the foundation of your infrastructure in Azure. So, weโ€™re happy to bring you a monthly update on Whatโ€™s new in Azure Networking.   In this blog post, weโ€™ll cover what new with Azure ...

TECHCOMMUNITY.MICROSOFT.COM