Identifying HTTP Authorization Failures

bundle

#1

###Bundle details and download
https://www.extrahop.com/bundles/txsteveo_eh/identifying-http-authorization-failures/

###Description
When a user attempts to access a website that requires authentication, be it basic or forms based authentication, and authentication hasn’t been provided the web server will respond with an HTTP Status Code 401 with a header requesting a type of authentication.

This bundle will watch for requests where authorization is provided, fails, and is requested again and will record the client IP, the Web Item being requested, and the status code response from the web server. It includes the trigger to record the appropriate metrics and the page to display the count and rate of these failed authentication attempts.