Detecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare Response
ID: 0728ac81-fbf5-53d2-a0e5-d9765f0b4e9a
STIX ID: report--0728ac81-fbf5-53d2-a0e5-d9765f0b4e9a
Feed Name: Elastic Security Labs
This article explains how to convert Traefik access logs into an active perimeter defense by ingesting logs into Elastic, using an ES|QL detection rule to identify web server discovery/fuzzing (high volumes of 403/404s per source IP and distinct URIs), and automating a Cloudflare workflow that appends offending IPs to a WAF blocklist. It covers required ingest pipeline changes (copying agent.name to host.name), tuning detection thresholds for homelabs, Cloudflare API token scope, the step-by-step workflow (retrieve/update/create rule, acknowledge alert), WAF size considerations, and testing with fuzzing tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
