Skip to content

Mitigation Rules

The Mitigation Rules subtab shows the rules that tell Vulnity when to automatically block an IP address. Each rule targets a specific attack vector.

Mitigation rules configuration

For every rule the table shows:

  • The alert type that triggers the block, such as brute force or suspicious queries.
  • Whether the rule is enabled or disabled.
  • The threshold — how many alerts must accumulate before the block is triggered.
  • The time window — the block duration once triggered.
  • The minimum alert severity required.
  • A description summarizing the resulting behavior.

When an IP address exceeds a rule’s threshold, it is blocked automatically for the configured duration and appears in Blocked IPs with the Auto source.