Malicious Requests

Last Updated At: 2025-10-15 16:09:52

this document guides you How to view and operate the malicious request alert list and policy configuration.

Background Information

The malicious request feature provides the ability to monitor and handle external request behaviors in real time, effectively identifying malicious request behaviors. If a host initiates a request to a malicious domain name, it will be identified and recorded. Upon detecting such malicious request behaviors, the system will provide you with real-time alerts.

Restriction Description

  • Malicious request monitoring supports professional edition and flagship edition hosts.
  • Malicious request interception only supports flagship edition hosts of Linux systems, and only supports blocking servers for DNS queries, not blocking traffic forwarding.

Alarm List

  1. Log in to the tenant-side console of Cloud Workload Protection Platform. In the left sidebar, select Intrusion Detection > Malicious Request to enter the malicious request page.
  2. On the malicious request page, the malicious request alert list can be viewed and related operations can be performed.
  • Filter: Support by hit policy type, status, last request time, inputting the host name in the search box, instance ID, IP address, malicious request domain name.
  • Process: mark as processed, add to allowlist, create blocking strategy, ignore, delete records.

Policy Configuration

Policy Management

Select Policy Configuration above the malicious request page to enter the policy configuration page.

  • Filter: Support by policy type, execution action, effective status, keywords filtering.

    Note:

    • System policies are built-in policies. Support switch, but not support adding, editing, or deleting.
    • It is recommended to keep system policies (standard) enabled. It is advisable to enable system policies (critical maintenance period) on demand during the critical maintenance period.
    • In user-defined policies, interception policies are only applicable to flagship hosts.