Aug. 24, 2023, 6:05 p.m. | zapbroob

System Weakness - Medium systemweakness.com

SOC142 — Multiple HTTP 500 Response — letsdefend.io

In this article we continue where we left off with letsdefend.io alert solutions, with Event ID 89: Multiple HTTP 500 Response (SOC142).

Let’s start with alert information.

 
EventID :89
Event Time :Apr, 18, 2021, 01:00 PM
Rule :SOC142 - Multiple HTTP 500 Response
Level :Security Analyst
Source Address :101.32.223.119
Source Hostname :101.32.223.119
Destination Address :172.16.20.6
Destination Hostname :SQLServer
Username :www-data
Request URL :https://172.16.20.6/userNumber=1 AND (SELECT * FROM Users) = 1
User Agent …

blue team cybersecurity incident response letsdefendio soc

Cyber Software Engineering, Senior Advisor

@ Peraton | Annapolis Junction, MD, United States

Cybersecurity Architect, Lead (NJUS)

@ NetJets | Columbus, OH, US, 43219

Security Operations Analyst

@ Commonwealth Financial Network | Waltham, MA, United States

Penetration Tester – Senior Associate - Cybersecurity

@ JPMorgan Chase & Co. | Buenos Aires, Argentina

Manager - Endpoint Security

@ Novo Nordisk | Bengaluru, Karnataka, IN

Senior Officer, Identity Access Management Administrator, Group Information Security (Contract)

@ UOB | Singapore (City Area), SG, 048624