⚙️ Detection Rule Configuration

Sliding-Window Brute-Force Detection

Flag IPs executing 5+ failed login attempts within a 2-minute sliding window.

Threat Intelligence Blacklist Correlation

Raise immediate MEDIUM severity alerts when blacklisted IPs interact with the system.

Internal Whitelist Filtering

Automatically suppress brute-force alerts for internal range IPs (127.0.0.1, 192.168.x.x).