Security Hub

Bring your software development workflows to security

logo-failed-auth

Suspicious rise of login failures

Signals & Triggers

On failed authentication
If an unusual volume is detected

Actions

  • Log the malicious request Log the malicious request
  • Report an incident Report an incident

Notifications

  • Send a Slack notification. Send a Slack notification.
  • Send an email to all team members Send an email to all team members
  • POST to your Webhook. POST to your Webhook.
  • Create an incident on PagerDuty (coming soon) Create an incident on PagerDuty (coming soon)

Details

A significant volume of failed logins has been detected on one or multiple accounts. It does not necessarily means that an attack is being performed, but something unusual is happening in your application.

This is the default incident category when Sqreen cannot qualify more precisely the scheme of attacks targeting user accounts.

Advanced details

Sqreen SDK enables you to track all login activities happening in your app.

Every minute Sqreen computes the signals and look for unusual failed login tentatives distributed over one or multiple accounts.

The signals computation happens on Sqreen’s backend based on the signals collected on all the instances of your applications. This collection happens asynchronously and is not slowing down your application performance.

Sqreen associates an authentication to a user account. You can choose what data is sent to Sqreen: email, userID etc. No other sensitive data is collected.

Language support

  • Ruby
  • Node.js
  • PHP
  • Python
  • Java

Data collected by Sqreen

Signals
  • Authentications (Sqreen SDK)

On attack

The peak is detected from recent authentication data.

Built for developers and modern apps

Get up and running in minutes just by installing our lightweight library. Enable plugins in just a couple of clicks.

  • Node.js
  • Ruby
  • PHP
  • Python
  • Java
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9

$ npm install --save sqreen

$ echo '{ "token": "your token" }' > sqreen.json

 

// This should be the first line of your app

require('sqreen');

$ echo "gem 'sqreen'" >> Gemfile

$ bundle install

$ echo "token: your token" > config/sqreen.yml

$ curl -s https://download.sqreen.io/php/install.sh > sqreen-install.sh && bash sqreen-install.sh your token

$ pip install sqreen

$ echo -e "[sqreen]\ntoken: your token" > sqreen.ini

 

# Insert at the top of your app file (typically wsgi.py or app.py)

import sqreen

sqreen.start()

$ curl https://download.sqreen.io/java/sqreen-latest-all.jar -o sqreen.jar

 

// Add JVM startup options:

-javaagent:/path/to/sqreen.jar -Dsqreen.token={{your token}}

Build amazing products. Keep them safe.

3 min installation · Try all features for 14 days · No credit card required Get started Request demo