Enforcement
Accepted
Attempts for this ban: 1
Last attempt: 2026-10-09T20:49:36.313463+00:00
Accepted at: 2026-10-09T20:49:37.257442+00:00
Acceptance records a successful command response. CrowdSec state is checked during confirmed enforcement runs; this page shows the stored outcome.
Reasons
- High severity exploit activity was observed, but only from a single node.
- Multiple stages of an attack chain were observed within a short time window.
- Observed behavior consistent with post-compromise activity, such as backdoors, webshells, or lateral movement.
- High-confidence indicators of post-exploitation activity were detected.
MITRE ATT&CK Mappings
- Tactics: Command and Control / Persistence, Initial Access, Reconnaissance
- Techniques: T1059, T1105, T1190, T1595
Evidence
- Last observed: 2026-10-09T18:59:34+00:00
- Last persisted: 2026-10-09T19:20:03.523278+00:00
- Nodes observed: 1
- Severity: CRITICAL
- TTL remaining: 13d 14h