Skip to content

LET : doc v2#1054

Draft
buixor wants to merge 8 commits intomainfrom
LET_revamp
Draft

LET : doc v2#1054
buixor wants to merge 8 commits intomainfrom
LET_revamp

Conversation

@buixor
Copy link
Copy Markdown
Contributor

@buixor buixor commented Mar 31, 2026

No description provided.

@aws-amplify-eu-west-1
Copy link
Copy Markdown

This pull request is automatically being deployed by Amplify Hosting (learn more).

Access this pull request here: https://pr-1054.d1to60jd2gb6y6.amplifyapp.com

| Firewall integration subscriptions | ✅ | ✅ |
| CVSS score | ✅ | — |
| CWE classification | ✅ | — |
| CrowdSec Analysis narrative | ✅ | — |
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is also part of fingerprints

2. **Monitor specific CVEs** for unpatched vulnerabilities in your environment. This gives you targeted exploitation intelligence.
3. **Create firewall integrations** subscribed to both CVEs and fingerprint rules to build layered blocklists.

For example, if you run WordPress:
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the real plus value would be to subscribe to the wordpress vendor no ?


The phases are determined by analyzing exploitation telemetry from the CrowdSec Network over time — they reflect real attacker behavior, not theoretical risk.

## The Five Phases
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we have 8 Exploitation phases:

InsufficientData = "insufficient_data"
EarlyExploitation = "early_exploitation"
FreshAndPopular = "fresh_and_popular"
TargetedExploitation = "targeted_exploitation"
MassExploitation = "mass_exploitation"
BackgroundNoise = "background_noise"
Unpopular = "unpopular"
WearingOut = "wearing_out"
Unclassified = "unclassified"

## Navigation

From a CVE page, you are able to view IPs exploiting the vulnerability:
The web interface is organized around a left sidebar with six sections:
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we now have a 9 sections.
missings ones are:

  • Releases
  • Settings
  • Documentation

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants