Operations

Monitor platform posture and manage operator workflows.

Operator view

Table: Security_events

Displaying rows 120401 - 120450 of 120479 (Page 2409 / 2410)
Entity Type Event time Action taken Ai reason Ai confidence score Ai details Event id
185.177.72.12 ip 2025-07-17 14:23:48 block Extensive reconnaissance for sensitive application configurations and credentials, coupled with LFI attempts and multiple IP blocking rules. 1.0 severity: Severity.critical ed032eb5-e7e5-4c24-9143-292704ac0f3b
185.177.72.11 ip 2025-07-17 14:23:48 block Targeting highly sensitive credentials, environment files, and server info pages, directly hit IP reputation deny rules. 1.0 severity: Severity.critical 209dfbbd-b587-4360-8ce2-d1f0cb88361b
185.177.72.205 ip 2025-07-17 14:23:48 block Attempting to access sensitive cloud credentials, environment files, and configuration, hitting LFI and IP blocking rules. 1.0 severity: Severity.critical 0bdba2e7-f9ec-4e75-a2d5-9add266deaea
185.177.72.204 ip 2025-07-17 14:23:48 block Targeted scanning for configuration files and source code repositories, triggering IP reputation deny rules. 1.0 severity: Severity.critical f888b6a2-8a1e-4472-8369-63a353cb3105
195.178.110.161 ip 2025-07-17 14:23:48 block Targeted scanning for sensitive JavaScript config files, JSON credentials, environment variables, and phpinfo, flagged by WAF and browser impersonation. 0.8999999761581421 severity: Severity.critical 7dbb4dec-8bfb-42f2-845c-6e0a51182f2a
194.50.16.252 ip 2025-07-17 14:23:48 block Targeting Spring Boot Actuator endpoints with command injection attempts and path obfuscation, indicating a direct exploit attempt. 1.0 severity: Severity.critical 60f78cc5-1a3c-4254-84cf-5b174ccc8619
2001:4878:8216:510:dddd:b98a:3a76:296c ip 2025-07-17 14:23:48 block Accessed obfuscated path 'oVBKUKnaa/nq36z4Dw/fOEJy35E/c0/uVaJz65XJ3SLLDS3/HyNpQmYB/HT8s/UgxbeHQ' which was previously flagged by WAF and linked to critical malicious activity in other blocked entities (e.g., AS132203, 3%7e2faa3a9db1c111de), indicating high potential for evasive or malicious intent. 0.949999988079071 severity: Severity.critical bda814e0-4d2b-4d18-acc7-5e1a4c1932ca
20.171.207.158 ip 2025-07-17 14:23:48 block All requests flagged by WAF, including suspicious and obfuscated paths targeting WordPress. 0.8500000238418579 severity: Severity.medium f4f5b020-7731-4713-a6c7-586b24463623
205.169.39.130 ip 2025-07-17 14:23:48 block Triggered an IP blocking rule due to burst activity, despite a lower percentage of detected threat requests. 0.8999999761581421 severity: Severity.critical 6e68e091-9f92-4237-a960-ed0688117046
2001:bc8:1f90:4:7ec2:55ff:fe9e:8476 ip 2025-07-17 14:23:48 block All requests flagged by WAF, including obfuscated paths and security alerts. 0.8500000238418579 severity: Severity.medium 8657f50b-b9d1-4e91-a84f-6a74a323a0a1
2001:bc8:1201:19:46a8:42ff:fe1b:ae29 ip 2025-07-17 14:23:48 block All requests flagged by WAF with suspicious paths and multiple security alerts. 0.8500000238418579 severity: Severity.medium 5bb8485f-2809-4c73-8d5d-2c7b8b84bf39
216.126.227.20 ip 2025-07-17 14:23:48 block Targeted WordPress specific attack paths like wlwmanifest.xml and xmlrpc.php, coupled with browser impersonation and IP blocking rules. 1.0 severity: Severity.critical b3196fb5-c1bc-4874-84f8-23e6ceb4d784
205.169.39.4 ip 2025-07-17 14:23:48 block High percentage of flagged requests and triggered an IP blocking rule due to burst activity. 0.8999999761581421 severity: Severity.critical 855690d6-bfa8-406a-858a-bdc498564b22
3.92.177.104 ip 2025-07-17 14:23:48 block Actively targeting WordPress wlwmanifest.xml and xmlrpc.php, directly triggering a WAF IPBLOCK rule. 1.0 severity: Severity.critical 75be4c10-92ba-4a92-b092-857cbb5234b8
2604:a880:400:d1:0:1:4cea:4001 ip 2025-07-17 14:23:48 block All requests flagged by WAF with suspicious obfuscated paths and security alerts. 0.8500000238418579 severity: Severity.medium b28fcf79-dfdf-49a6-9d85-c23c6a2e5d03
51.38.105.105 ip 2025-07-17 14:23:48 block Extensive scanning for sensitive configuration files, credentials, and PHP info pages, with a high threat detection rate and browser impersonation. 0.8999999761581421 severity: Severity.critical 053c222c-130e-4619-8850-58822f6590ea
34.116.246.85 ip 2025-07-17 14:23:48 block All requests flagged by WAF with obfuscated paths and multiple security alerts. 0.8500000238418579 severity: Severity.medium c6b7a011-67eb-4c4b-9c17-42162769d9f2
34.116.172.61 ip 2025-07-17 14:23:48 block All requests flagged by WAF with obfuscated paths and multiple security alerts. 0.8500000238418579 severity: Severity.medium d1248a47-f94b-4f50-9ece-a1e1253f90e2
66.249.77.104 ip 2025-07-17 14:23:48 block All requests flagged by WAF and triggered security alerts, indicating malicious activity. 0.949999988079071 severity: Severity.critical 1f5a137b-63f3-4925-8be3-7084cea634b9
AS211590 asn 2025-07-17 14:23:48 block Aggregated traffic from this ASN demonstrates a 100% threat detection rate involving widespread probing for sensitive files, credentials, and actively attempting LFI attacks, triggering multiple critical IP blocking and reputation rules. 1.0 severity: Severity.critical 669d1562-9165-4523-927a-20b4113d824b
AS16276 asn 2025-07-17 14:23:48 block Aggregated traffic from this ASN shows a very high threat detection rate with diverse malicious activities, including directory scanning and sensitive file probing, consistent with multiple compromised or malicious hosts. 1.0 severity: Severity.critical 9765020a-0848-454b-9937-d238bf50f9ae
AS132203 asn 2025-07-17 14:23:48 block High volume of 100% flagged requests targeting WordPress endpoints and including multiple obfuscated paths, indicating aggressive and suspicious automated activity. 0.8999999761581421 severity: Severity.critical 8e30c2c4-3928-4225-abee-3f18aa934f70
3%7e7bcf51bfc0d0b65f tls 2025-07-17 14:23:48 block Extensive reconnaissance for sensitive application configurations and credentials, coupled with LFI attempts and multiple IP blocking rules, associated with this TLS fingerprint. 1.0 severity: Severity.critical 343d627e-39c5-4ecb-b334-f6ebb75884b7
3%7e2faa3a9db1c111de tls 2025-07-17 14:23:48 block High volume of 100% flagged requests targeting WordPress attack vectors, sensitive configurations, and including obfuscated paths, directly triggering WAF IPBLOCK rules. 1.0 severity: Severity.critical f7067bd3-ebdc-4953-9994-9b14e2324890
3%7ee35ec11fcbea7346 tls 2025-07-17 14:23:48 block Very high percentage of flagged requests, including obfuscated paths, directly triggering an IP blocking rule due to burst activity. 0.8999999761581421 severity: Severity.critical 6d292070-26b5-4b89-b477-98a8a3a53a85
3%7ede293936a8dc4153 tls 2025-07-17 14:23:48 block All requests flagged by WAF, targeting sensitive WordPress endpoints, containing suspicious obfuscated paths, and showing browser impersonation. High confidence of malicious intent. 0.949999988079071 severity: Severity.critical fa46e145-7307-49f3-95ed-918240638da9
3%7ebaae1457ad64ff16 tls 2025-07-17 14:23:48 block All requests flagged by WAF, including obfuscated paths, and multiple security rule hits indicating reconnaissance. 0.8999999761581421 severity: Severity.critical 95fe27bb-649a-4f08-92f2-43d341e263df
UNKNOWN tls 2025-07-17 14:23:48 block Comprehensive and aggressive attack patterns including sensitive file probing, WordPress exploit attempts, web shell probing, LFI, and triggering multiple critical IP blocking and reputation rules. 1.0 severity: Severity.critical 6614164e-e8f9-40e7-ad6b-c4dbbccb9fea
2001:4878:8216:510:dddd:b98a:3a76:296c ip 2025-07-17 14:18:33 block Accessed obfuscated path 'oVBKUKnaa/nq36z4Dw/fOEJy35E/c0/uVaJz65XJ3SLLDS3/HyNpQmYB/HT8s/UgxbeHQ' which was previously flagged by WAF and linked to critical malicious activity in other blocked entities (e.g., AS132203, 3%7e2faa3a9db1c111de), indicating high potential for evasive or malicious intent. 0.949999988079071 severity: Severity.critical fe6292df-b233-49a3-80bb-fe7980cf3f94
2001:4878:8216:510:dddd:b98a:3a76:296c ip 2025-07-17 14:13:22 ignore No detected threat requests, no WAF flags, and no security rule hits, indicating normal benign traffic. 0.949999988079071 severity: Severity.low 9395ed8c-394a-468d-94c6-0b5b1ffd13db
2001:4878:8216:510:dddd:b98a:3a76:296c ip 2025-07-17 14:08:23 ignore No malicious activity detected, no WAF flags, and no security rule hits. Appears to be benign traffic. 0.949999988079071 severity: Severity.low e5791f1c-4ae0-4a0e-a412-4577ec03f2dc
2001:4878:8216:510:dddd:b98a:3a76:296c ip 2025-07-17 14:03:28 ignore No detected threat requests, WAF flags, or security rule hits observed. Despite an unusual obfuscated path, the overall activity indicates benign behavior. 0.8999999761581421 severity: Severity.low c1d95f1e-8512-435c-9379-abf0e898502f
2001:4878:8216:510:dddd:b98a:3a76:296c ip 2025-07-17 13:58:17 ignore No detected threat requests, no WAF flags, and no security rule hits found, suggesting benign activity or a resolved threat. 0.8999999761581421 severity: Severity.low b9484ee1-0fea-410b-ada5-52c38426b845
2001:4878:8216:510:dddd:b98a:3a76:296c ip 2025-07-17 13:53:23 watchlist Entity accessed an obfuscated path also observed in patterns from previously blocked malicious entities. While no direct WAF flags or security rule hits were triggered for its requests, its activity warrants continued monitoring. 0.699999988079071 severity: Severity.medium 5ca17409-9808-420a-8bdd-17d4e2e88772
2001:4878:8216:510:dddd:b98a:3a76:296c ip 2025-07-17 13:48:22 ignore No detected threat requests, no WAF flags, and no security rule hits. The accessed paths appear to be legitimate website content. 1.0 severity: Severity.low 226c33cc-cf38-4ded-a2ef-3cbb425c882f
157.180.49.118 ip 2025-07-17 13:43:34 block All requests flagged by WAF and multiple security rule hits, indicating malicious probing. 0.8500000238418579 severity: Severity.medium 8c8418fe-5e6a-4d9f-8c65-044b15e40038
123.6.49.50 ip 2025-07-17 13:43:34 block All requests flagged by WAF with multiple security rule hits, indicating high confidence malicious activity. 0.8999999761581421 severity: Severity.critical e1827f52-cc8a-478e-9591-6086f81b35e6
20.171.207.158 ip 2025-07-17 13:43:34 block All requests flagged by WAF, including suspicious and obfuscated paths targeting WordPress. 0.8500000238418579 severity: Severity.medium 81fedf86-9f24-4d57-8b55-02e852f2cc10
2001:bc8:1f90:4:7ec2:55ff:fe9e:8476 ip 2025-07-17 13:43:34 block All requests flagged by WAF, including obfuscated paths and security alerts. 0.8500000238418579 severity: Severity.medium 01d8e868-23a1-4389-bb4b-4f7af7fb39b8
2001:bc8:1201:19:46a8:42ff:fe1b:ae29 ip 2025-07-17 13:43:34 block All requests flagged by WAF with suspicious paths and multiple security alerts. 0.8500000238418579 severity: Severity.medium b8585d5b-f3dd-4256-889d-b230594ed347
2604:a880:400:d1:0:1:4cea:4001 ip 2025-07-17 13:43:34 block All requests flagged by WAF with suspicious obfuscated paths and security alerts. 0.8500000238418579 severity: Severity.medium b3506106-602a-4886-b59c-c77c123f2168
34.116.246.85 ip 2025-07-17 13:43:34 block All requests flagged by WAF with obfuscated paths and multiple security alerts. 0.8500000238418579 severity: Severity.medium a1340ab1-09f5-4d35-95e6-9a403ce95e27
34.116.172.61 ip 2025-07-17 13:43:34 block All requests flagged by WAF with obfuscated paths and multiple security alerts. 0.8500000238418579 severity: Severity.medium ccf7a585-382f-4dcb-9db7-9005c03b20b4
66.249.77.104 ip 2025-07-17 13:43:34 block All requests flagged by WAF and triggered security alerts, indicating malicious activity. 0.949999988079071 severity: Severity.critical ae13043d-a17d-4371-a5c2-81597bc1be85
3%7ede293936a8dc4153 tls 2025-07-17 13:43:34 block All requests flagged by WAF, targeting sensitive WordPress endpoints, containing suspicious obfuscated paths, and showing browser impersonation. High confidence of malicious intent. 0.949999988079071 severity: Severity.critical 759207c2-626b-47d9-b0a5-0c88ef9eb398
3%7ebaae1457ad64ff16 tls 2025-07-17 13:43:34 block All requests flagged by WAF, including obfuscated paths, and multiple security rule hits indicating reconnaissance. 0.8999999761581421 severity: Severity.critical ae9d136e-0747-4523-9535-b9cb6bbed74e
185.177.72.205 ip 2025-07-17 13:39:09 block Attempting to access sensitive cloud credentials, environment files, and configuration, hitting LFI and IP blocking rules. 1.0 severity: Severity.critical 843751af-169a-448f-8a24-e3e3c4681bf3
195.178.110.161 ip 2025-07-17 13:39:09 block Targeted scanning for sensitive JavaScript config files, JSON credentials, environment variables, and phpinfo, flagged by WAF and browser impersonation. 0.8999999761581421 severity: Severity.critical edc5639c-0d86-404e-b5d2-c1c25b61073d
194.50.16.252 ip 2025-07-17 13:39:09 block Targeting Spring Boot Actuator endpoints with command injection attempts and path obfuscation, indicating a direct exploit attempt. 1.0 severity: Severity.critical 1149b1f6-2ad8-4853-a2ed-823e6501be11
2001:4878:8216:510:dddd:b98a:3a76:296c ip 2025-07-17 13:39:09 ignore No malicious activity detected by WAF or security rules; all requests were legitimate. 1.0 severity: Severity.low 4bff7158-ec09-4f0a-8860-805664b4316f
← Back to Tables