Security Dashboard

Unique IPs

34

Bot Requests

318

WAF Rule Hits

75

Requests by Country (Map)

Recent AI Decisions Feed

All requests (100%) from this IP were flagged by WAF, indicating persistent malicious probing targeting WordPress endpoints and triggering security alerts. Confidence: 100% · 2025-12-05 18:50
AS48090 (ASN)
Associated with IP 45.148.10.246, which demonstrated extensive probing of sensitive files, had all requests flagged by WAF, and triggered critical deny rules including LFI-ANOMALY and IPBLOCK. Confidence: 100% · 2025-12-04 12:34
Extensive probing of sensitive configuration files and backups (e.g., .env, config/mail), all requests (100%) flagged by WAF, and multiple critical deny rules triggered including LFI-ANOMALY and IPBLOCK. Confidence: 100% · 2025-12-04 12:34
No security rule hits, WAF flags, or detected threat requests, and no activity for over a month. Entity is no longer considered suspicious. Confidence: 95% · 2025-12-02 14:22
No current security rule hits, WAF flags, or detected threat requests. Entity has not shown recent malicious behavior, contradicting previous AI assessment. Confidence: 90% · 2025-12-02 14:22
All requests (100%) were flagged by WAF and targeted 'wp-login.php', triggering security alerts indicative of a brute-force or credential stuffing attack. Confidence: 100% · 2025-12-02 14:22
3%7e67c0ea0c99e03401 (TLS Fingerprint)
TLS fingerprint associated with an IP (4.189.168.36) that had all requests flagged by WAF, bot impersonation, and probing of sensitive paths. Associated ASN AS8075 is blocklisted. Confidence: 100% · 2025-11-30 15:39
All requests (100%) flagged by WAF with bot impersonation and probing of sensitive paths. Associated ASN AS8075 is already blocklisted for persistent malicious activity. Confidence: 100% · 2025-11-30 15:39
IP accessed sensitive WordPress login path (wp-login.php) and is from an ASN with a history of similar suspicious WordPress probing, indicating potential reconnaissance or enumeration attempts. Confidence: 60% · 2025-11-30 15:29
Multiple critical WAF deny rules triggered, including LFI, command injection, XSS, and bot impersonation, indicating severe malicious probing and exploit attempts. All accessed paths were flagged. Confidence: 100% · 2025-11-30 14:03

Requests per Day

Threat Actions (Alert vs Deny)

Top Attacking IPs

Top Requested Paths