SlideShare a Scribd company logo
Azure App Gateway and Log Analytics under Penetration Tests
Azure App Gateway and Log Analytics under Penetration Tests
www.roykim.ca
roy@roykim.ca
Azure App Gateway and Log Analytics under Penetration Tests
Azure App Gateway and Log Analytics under Penetration Tests
Open Web Application Security Project
OWASP ModSecurity Core Rule Set (CRS)
OWASP Top 10 Most Critical Web Application Security Risks
A1:2017-Injection
A2:2017-Broken Authentication
A3:2017-Sensitive Data Exposure
A4:2017-XML External Entities (XXE)
A5:2017-Broken Access Control
A6:2017-Security Misconfiguration
A7:2017-Cross-Site Scripting (XSS)
A8:2017-Insecure Deserialization
A9:2017-Using Components with Known Vulnerabilities
A10:2017-Insufficient Logging&Monitoring
*
https://www.zaproxy.org/
https://github.com/zaproxy/zap-hud
Azure App Gateway and Log Analytics under Penetration Tests
Azure Application Gateway
 An application delivery controller
 layer 7 load balancing/routing capabilities
 web application firewall.
OWASP
ModSecurity Core Rule Set
https://docs.microsoft.com/en-us/azure/azure-monitor/azure-monitor-rebrand#log-analytics-redefinition
• Configuration
• Penetration Test
• Monitoring with Log Analytics
• Alert
* see appendix slides for demo screenshots
Azure App Gateway and Log Analytics under Penetration Tests
roy@roykim.ca
Azure App Gateway and Log Analytics under Penetration Tests
Azure App Gateway and Log Analytics under Penetration Tests
Azure App Gateway and Log Analytics under Penetration Tests
Azure App Gateway and Log Analytics under Penetration Tests
Azure App Gateway and Log Analytics under Penetration Tests

More Related Content

PDF
淺談WAF在AWS的架構_20171027
PDF
Better API Security with Automation
PPTX
How to leverage Evident Security Platform for DFARS-NIST 800-171 AWS Accounts
PPTX
Microservices docker-security
PDF
Launching a Highly-regulated Startup in the Public Cloud
PPTX
OpenStack at Cisco, June 2015
PDF
aOS Monaco 2019 - A7 - Sécurisez votre SI et vos services Office 365 partie 2...
PDF
Serverless DevSecOps: Why We Must Make it Everyone's Problem | Hillel Solow
淺談WAF在AWS的架構_20171027
Better API Security with Automation
How to leverage Evident Security Platform for DFARS-NIST 800-171 AWS Accounts
Microservices docker-security
Launching a Highly-regulated Startup in the Public Cloud
OpenStack at Cisco, June 2015
aOS Monaco 2019 - A7 - Sécurisez votre SI et vos services Office 365 partie 2...
Serverless DevSecOps: Why We Must Make it Everyone's Problem | Hillel Solow

What's hot (16)

PDF
Microservices: Notes From The Field
PPTX
Building Automated Governance Using Code, Platform Services & Several Small P...
PDF
20180514 _aws data-security_aws.compressed
PDF
What's New With PureSec | April 2019
PPTX
Microsoft Azure News - April 2021
PDF
CSS17: Houston - Introduction to Security in the Cloud
PPTX
CSS17: Atlanta - Realities of Security in the Cloud
PDF
CSS17: Houston - Protecting Web Apps
PDF
Mohamed aliassakerresumev5 2018
PPTX
Realizing the Full Potential of Cloud-Native Application Security
PDF
Apcera: Agility and Security in Docker Delivery
PDF
[201702]Qubit Security Pitch deck
PDF
Haal de mist uit de monitoring van je cloud met System Center 2012 R2 Operati...
PPTX
Micro segmentation – a perfect fit for microservices
PPTX
#ALSummit: Alert Logic & AWS - AWS Security Services
PPTX
CSS17: DC - The AWS Shared Responsibility Model in Practice
Microservices: Notes From The Field
Building Automated Governance Using Code, Platform Services & Several Small P...
20180514 _aws data-security_aws.compressed
What's New With PureSec | April 2019
Microsoft Azure News - April 2021
CSS17: Houston - Introduction to Security in the Cloud
CSS17: Atlanta - Realities of Security in the Cloud
CSS17: Houston - Protecting Web Apps
Mohamed aliassakerresumev5 2018
Realizing the Full Potential of Cloud-Native Application Security
Apcera: Agility and Security in Docker Delivery
[201702]Qubit Security Pitch deck
Haal de mist uit de monitoring van je cloud met System Center 2012 R2 Operati...
Micro segmentation – a perfect fit for microservices
#ALSummit: Alert Logic & AWS - AWS Security Services
CSS17: DC - The AWS Shared Responsibility Model in Practice
Ad

Similar to Azure App Gateway and Log Analytics under Penetration Tests (20)

PDF
Better API Security With A SecDevOps Approach
PDF
SecDevOps for API Security
PPTX
Brocade vADC Portfolio Overview 2016
PPT
OWASP an Introduction
PPTX
Azure serverless security
PDF
淺談WAF在AWS的架構
PPTX
Owasp top 10 web application security risks 2017
PDF
Owasp qatar presentation top 10 changes 2013 - Tarun Gupta
PPTX
OWASP_Top_Ten_Proactive_Controls version 2
PPTX
OWASP_Top_Ten_Proactive_Controls_v2.pptx
PPTX
OWASP_Top_Ten_Proactive_Controls_v2.pptx
PDF
OWASP top10 2017, Montpellier JUG de Noel
PDF
AppSec Tel Aviv - OWASP Top 10 For JavaScript Developers
PPTX
OWASP_Top_Ten_Proactive_Controls_v2.pptx
PPTX
5 Absolutely Beautiful Things about Platform as a Service (PaaS)
PDF
Web hackingtools cf-summit2014
PPTX
OWASP_Top_Ten_Proactive_Controls_v32.pptx
PDF
The automated (ethical) hacker in you - test automation day nl 2018
PDF
Web hackingtools 2015
PDF
Web hackingtools 2015
Better API Security With A SecDevOps Approach
SecDevOps for API Security
Brocade vADC Portfolio Overview 2016
OWASP an Introduction
Azure serverless security
淺談WAF在AWS的架構
Owasp top 10 web application security risks 2017
Owasp qatar presentation top 10 changes 2013 - Tarun Gupta
OWASP_Top_Ten_Proactive_Controls version 2
OWASP_Top_Ten_Proactive_Controls_v2.pptx
OWASP_Top_Ten_Proactive_Controls_v2.pptx
OWASP top10 2017, Montpellier JUG de Noel
AppSec Tel Aviv - OWASP Top 10 For JavaScript Developers
OWASP_Top_Ten_Proactive_Controls_v2.pptx
5 Absolutely Beautiful Things about Platform as a Service (PaaS)
Web hackingtools cf-summit2014
OWASP_Top_Ten_Proactive_Controls_v32.pptx
The automated (ethical) hacker in you - test automation day nl 2018
Web hackingtools 2015
Web hackingtools 2015
Ad

More from Roy Kim (13)

PPTX
Microsoft Reactor Toronto 5/5/2020 | Azure Kubernetes In Action - Running and...
PPTX
Azure AD App Proxy Login Scenarios with an On Premises Applications - TSPUG
PPTX
Azure Key Vault with a PaaS Architecture and ARM Template Deployment
PPTX
Applying Advanced Techniques to Azure Web Apps
PDF
Big Data Analytics from Azure Cloud to Power BI Mobile
PDF
Design and Configure Azure App Service Web Apps
PPTX
SharePoint 2016 Hybrid Overview
PPTX
SharePoint Hosted Add-in with AngularJS and Bootstrap
PPTX
Designing for SharePoint Provider Hosted Apps
PDF
Microsoft Azure For Solutions Architects
PPTX
SharePoint 2013 Hosted App Presentation by Roy Kim
PPT
Networking For Application Developers by Roy Kim
PPTX
SharePoint Saturday 2010 - SharePoint 2010 Content Organizer Feature
Microsoft Reactor Toronto 5/5/2020 | Azure Kubernetes In Action - Running and...
Azure AD App Proxy Login Scenarios with an On Premises Applications - TSPUG
Azure Key Vault with a PaaS Architecture and ARM Template Deployment
Applying Advanced Techniques to Azure Web Apps
Big Data Analytics from Azure Cloud to Power BI Mobile
Design and Configure Azure App Service Web Apps
SharePoint 2016 Hybrid Overview
SharePoint Hosted Add-in with AngularJS and Bootstrap
Designing for SharePoint Provider Hosted Apps
Microsoft Azure For Solutions Architects
SharePoint 2013 Hosted App Presentation by Roy Kim
Networking For Application Developers by Roy Kim
SharePoint Saturday 2010 - SharePoint 2010 Content Organizer Feature

Recently uploaded (20)

PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Electronic commerce courselecture one. Pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PPTX
Big Data Technologies - Introduction.pptx
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Empathic Computing: Creating Shared Understanding
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
cuic standard and advanced reporting.pdf
PDF
MIND Revenue Release Quarter 2 2025 Press Release
Network Security Unit 5.pdf for BCA BBA.
Electronic commerce courselecture one. Pdf
Encapsulation_ Review paper, used for researhc scholars
Mobile App Security Testing_ A Comprehensive Guide.pdf
Reach Out and Touch Someone: Haptics and Empathic Computing
Big Data Technologies - Introduction.pptx
Advanced methodologies resolving dimensionality complications for autism neur...
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Empathic Computing: Creating Shared Understanding
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Spectral efficient network and resource selection model in 5G networks
Per capita expenditure prediction using model stacking based on satellite ima...
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Review of recent advances in non-invasive hemoglobin estimation
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Diabetes mellitus diagnosis method based random forest with bat algorithm
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
cuic standard and advanced reporting.pdf
MIND Revenue Release Quarter 2 2025 Press Release

Azure App Gateway and Log Analytics under Penetration Tests

Editor's Notes

  • #12: https://www.modsecurity.org/crs/