Session Hijacking Notification Risk Extractor
Description
Risk Extractor that extracts the notification flag of the Airlock Gateway (WAF) client fingerprinting (CFP)
request. The notification flag indicates whether client fingerprinting has detected a potential session hijacking.
No tags are granted, if the request does not contain a CFP notification environment cookie.
May be used by
Properties
Tags On Detected Session Hijacking (
tagsOnDetectedSessionHijacking) Description
The tags to grant if session hijacking has been detected. This means that the CFP notification flag is TRUE.
Attributes
Plugin-List
Optional
Assignable plugins
Tags On Session Without Hijacking (
tagsOnSessionWithoutHijacking) Description
The tags to grant if no session hijacking has been detected. This means that the CFP notification flag is FALSE.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)
type: SessionHijackingNotificationRiskExtractor
id: SessionHijackingNotificationRiskExtractor-xxxxxx
displayName:
comment:
properties:
tagsOnDetectedSessionHijacking:
tagsOnSessionWithoutHijacking: