Enforcement
Accepted
Attempts for this ban: 1
Last attempt: 2026-10-10T02:00:06.320452+00:00
Accepted at: 2026-10-10T02:00:08.034849+00:00
Acceptance records a successful command response. CrowdSec state is checked during confirmed enforcement runs; this page shows the stored outcome.
Reasons
- High severity exploit activity was observed, but only from a single node.
- Multiple stages of an attack chain were observed within a short time window.
- Observed behavior consistent with post-compromise activity, such as backdoors, webshells, or lateral movement.
- High-confidence indicators of post-exploitation activity were detected.
MITRE ATT&CK Mappings
- Tactics: Command and Control / Persistence, Initial Access, Reconnaissance
- Techniques: T1059, T1105, T1190, T1595
Evidence
- Last observed: 2026-10-10T01:38:57+00:00
- Last persisted: 2026-10-10T02:00:03.907248+00:00
- Nodes observed: 1
- Severity: CRITICAL
- TTL remaining: 13d 21h