Event type | Event description |
API calls from abnormal regions | Requests that normally access this API are concentrated in a specific region. A large number of requests from other regions are found to have called this API, indicating a potential abnormal call. |
API calls from abnormal source IPs | IP addresses that normally access this API are concentrated in a specific network segment. A large number of abnormal IP address segments are found to have called this API, indicating a potential abnormal call. |
API calls from abnormal clients | Clients that normally access this API are primarily of a specific type. A large number of requests are found to have called this API through other types of clients, indicating a potential abnormal call. |
Event type | Event description |
Web Attacks | The API is frequently subjected to more than ten types of Web attacks, including SQL injection, XSS attacks, command injection, unauthorized access to core files, file upload attacks, malicious scanning, trojan backdoor attacks, XML injection, Web application vulnerability attacks, LDAP injection, server-side request forgery, server-side template injection vulnerabilities, unauthorized access vulnerabilities, and non-compliant protocols. |
Event type | Event description |
Unauthorized Access Successful | The interface exhibits suspected unauthorized access. This means that users are accessing and performing CRUD operations on resources that require authentication without any authorization. |
Vertical Privilege Escalation | The interface exhibits suspected vertical privilege escalation. This type of escalation occurs when a user attempts to elevate their own permission level to access or operate on resources or data that are above their current permission level. |
Horizontal Privilege Escalation | The interface exhibits suspected horizontal privilege escalation. This type of escalation occurs when a user attempts to access resources or data belonging to other users at the same permission level. |
Missing Username and Password | The request lacks the necessary user and password information, which may indicate that an attacker is attempting to attack the business, such as through Fuzzing. |
Missing User Value | The request lacks the necessary user information, such as user ID or username, which may indicate that an attacker is attempting to attack the business, such as through Fuzzing. |
Missing Login Action | The request lacks the necessary login action, for example, the login request is missing the login action parameter, which may indicate that an attacker is attempting to attack the business, such as through Fuzzing. |
Event type | Event description |
Brute-force attack | Attackers use automated tools to perform brute-force attacks on target system passwords. Attackers typically use dictionary attacks or brute-force tools to try multiple password combinations until the correct one is found. |
Credential stuffing attack | Attackers use known username and password combinations to attempt to log in to target systems, typically by leveraging leaked user information for the attack. Attackers commonly use leaked username and password combinations to try logging in to other websites or systems to see if they can gain access to the target system. |
Malicious registration | This means that attackers use false or stolen user information to register, typically to carry out other malicious activities, such as sending spam emails. |
Event type | Event description |
API abuse | Users or attackers make frequent requests to the API, exceeding normal usage limits, which may impose a burden on the system or create security risks. Attackers typically use automated tools to send a large number of requests in an attempt to consume system resources or perform other malicious actions. |
SMS API flooding | Attackers use automated tools to make frequent requests to the SMS API, typically to conduct malicious activities such as SMS bombing or consuming SMS resources. |
Captcha API flooding | Attackers use automated tools to make frequent requests to the Captcha API, typically to conduct malicious activities such as Captcha bypass or Captcha resource consumption. |
Event type | Event description |
Excessive Sensitive Data Retrieval | Users or attackers obtain a significant volume of sensitive data by calling this API, which may lead to sensitive data leaks and internal information insecurity. |
Unauthorized Access to Obtain Sensitive Information | Users or attackers access sensitive data within the system without authorization, leading to sensitive data leaks and internal information insecurity. |
Weak Encryption Transmission | Passwords, keys, and other sensitive content transmitted in the request body only use reversible encoding methods such as Base64 and Hex (hexadecimal), or employ encryption algorithms with insufficient strength (such as DES and RC4), rather than secure encryption methods that meet security standards (such as AES and RSA). Attackers can easily decode or crack this content, leading to sensitive information leaks. |
Event type | Event description |
API returns abnormal error messages. | The interface returns unhandled error messages, such as stack traces and framework default errors. This information may expose code logic, dependency library versions, or server configurations, helping attackers precisely locate vulnerabilities. |
API returns server sensitive information | The API returns server sensitive data, such as server paths, key files, and cloud service AK/SK. This data may be used for lateral movement, privilege escalation, or direct intrusion into the production environment. Immediately block and fix the source of the leak. |
API returns database error messages. | The API returns database-related error messages. This may expose table structures, SQL statements, or database types, which attackers can leverage to construct SQL injection or targeted attacks. |
Abnormal API response status | The API continuously returns abnormal server response statuses. This behavior may indicate malicious stress testing, resource exhaustion attacks, or origin server failures. Investigate whether it involves DDoS or application-layer vulnerability exploitation. |


Field Name | Description |
Security events | Total number of risk events under the current domain. |
Detected today | Total number of newly added risk events under the current domain today. |
Detected | Total number of risk events in the newly discovered state under the current domain. |
Handle | Total number of risk events in the resolved state under the current domain. |
In progress | Total number of risk events in the in-process state under the current domain. |
Ignored | Total number of risk events in the ignored state under the current domain. |
Disabled | Total number of risk events in the closed state under the current domain. |
Field Name | Description |
Event ID | Risk event name. |
Event Type | Risk event type. |
Event Level | Risk level of the risk event. |
Related Domain | Domain to which the risk event belongs. |
Related API | Name of the API associated with the risk event. |
Status | Current status of the risk event. Newly Discovered: Risk events that are newly discovered and not yet confirmed. In Progress: Risk events that are being confirmed and for which relevant rules are being configured. This status provides handling suggestions (such as CC/Access Control/BOT) for the event type, allowing you to add the corresponding rules with one click. Confirmed: Risk events for which the risk has been confirmed and handling rules have been added. Ignored: The risk event has been confirmed as not requiring handling and has been ignored. Closed: The event has been closed after the access and attack traffic are observed and it is confirmed that the event can be completely closed. |
Detection Time | The earliest time when the risk event was detected. |
Last Update | The latest time when the risk event was updated. |
Operation | Handle event and View details. |

Field Name | Description |
Basic information | Includes Event ID, Event type, Occurred, Update time, Related API, Associated domain, and Event details. |
Suggestion Rule | Provides corresponding event handling recommendations based on the event type. You can click Add now to add the corresponding handling rule. |
Rule added | Status of Added Rules. |
Attacker details | Event Attack Source Details. |
Change history | Event Status Change History. |

Apakah halaman ini membantu?
Anda juga dapat Menghubungi Penjualan atau Mengirimkan Tiket untuk meminta bantuan.
masukan