cscli collections install openappsec/openappsecA collection for open-appsec that allow to ban IPs that made requests that open-appsec blocked in the waf.
This collection handle most of the waapIncidentType that open-appsec can generate.
SQL InjectionPath TraversalLDAP InjectionRemote Code ExecutionVulnerability ScanningCross Site ScriptingXML External EntityEvasion TechniquesGeneralURL instead of fileCross Site Request ForgeryCross Site RedirectOpen RedirectSchema ValidationBot ProtectionError DisclosureError LimitIllegal http method violationHttp limit violationRequest Rate LimitExample acquisition for this collection :
1source: file2filenames:3 - /var/log/nano_agent/cp-nano-http-transaction-handler.log*4labels:5 type: openappsec