Skip to main content
shafiq23
Staff & Editor
Staff & Editor
February 25, 2025

Technical Tip: Known attack signature exception rule

  • February 25, 2025
  • 0 replies
  • 398 views
Description This article describes how to configure signature exception rule based on generated attack log in Attack Log page.
Scope FortiAppSec Cloud WAF.
Solution

For false positive blockings requiring exceptions for specific URLs or other supported parameters, verify the triggered signature details and validate whether the request is legitimate.

 

Note:

Msg ID observed in the client browser can be used to filter specific attack logs.

 

  1. Navigate to Threat Analytics -> Attack Logs and selectthe  ‘>’ icon to open attack log details.

 

2.png

 

Validate whether the triggered signature is a false positive. A new window pops up when selecting the Signature ID number associated with the attack log and shows details of the triggered signature.

 

3.PNG

 

  1. Select ‘Add Exception’ in the details pane.
  2. Specify the exception method and select 'OK'.

 

Signature-exception.png

 

The list of created exceptions will be updated in WAF -> Application -> Security Rules -> Known Attacks -> Signature Based Detection Exception Rule.

 

1.PNG

 

For more information about the signature exception rule and supported options, refer to the FortiAppSec Cloud User Guide:
Known Attacks