ModSecurity rules for Wordpress running on IIS server for blocking multiple login tries (unable to use Locationmatch)

September 12, 2019

has someone tried to run ModSecurity on IIS server and block login attempts to wp-login.php (xmlrpc.php too) after X tries in some period of time (or without any period of time but after Z seconds substract -1 from tries number), then block IP for Y number of seconds?

Every example I could find (like this one: is using "Locationmatch" tag which is not available on IIS.

Thank you

