Mitigation Rules
The Mitigation Rules subtab shows the rules that tell Vulnity when to automatically block an IP address. Each rule targets a specific attack vector.

What each rule defines
Section titled “What each rule defines”For every rule the table shows:
- The alert type that triggers the block, such as brute force or suspicious queries.
- Whether the rule is enabled or disabled.
- The threshold — how many alerts must accumulate before the block is triggered.
- The time window — the block duration once triggered.
- The minimum alert severity required.
- A description summarizing the resulting behavior.
When an IP address exceeds a rule’s threshold, it is blocked automatically for the configured duration and appears in Blocked IPs with the Auto source.
Where rules are managed
Section titled “Where rules are managed”Next steps
Section titled “Next steps”- SIEM rules documentation — configure the rules from the panel.
- Blocked IPs — see the blocks these rules produce.
- Mitigation synchronization — how the configuration reaches the site.