Web attack · Automatic response

From six signals to an automatic block

One attacker, five different techniques, six separate alerts from three defense layers — and zero human intervention up to the block. This is how Aegis correlation turns scattered signals into a single decision.

🏢 Web hosting / WordPress ⏱️ Attack duration: ~9 min 🛡️ Outcome: source blocked, 0 successful requests after the block
4MITRE ATT&CK techniques from the same source
6separate alerts merged into 1 incident
188malicious requests recorded
0successful requests after the block

Context

This concerns a WordPress web application in a shared hosting environment protected by Aegis. The client and exact domain are anonymized — every figure, technique and timeline in this study comes directly from the incident record (WORM ledger), without embellishment.

The attack was not one “loud” event but a series of seemingly unrelated signals scattered across the WAF, SIEM and network layer. Individually, each is easily lost in the noise. The value of a SOC is precisely in joining them into one story — and reacting to it while the attack is still underway.

What happened

In just under ten minutes, the same source (31.45.239.xxx) went through five phases in turn:

How Aegis responded

Each of these phases raised its own alert — six in total, from three different defense layers (WAF, authentication SIEM, network detection). The decisive moment was not any single detection, but correlation:

Response without waiting.

From the moment correlation confirmed the attack to blocking the source at the firewall, less than a minute passed. After the block, not a single further request from that IP reached the application.

Evidence trail

The automatic response is not the end of the story — every decision leaves a trail that can be audited:

That is the difference between “the system blocked something” and “we can show exactly what happened, why and in what order” — whether for an internal audit or NIS2 records.

🔒
On anonymization: the client's identity and domain were removed deliberately. The techniques, numbers and timeline are faithfully carried over from the recorded incident. The attacker's source IP is shown because it is part of a public threat, not the client's data.

Want your defense to look like this too?

Aegis connects the signals that individual tools miss — and reacts while the attack is still underway.

Book a call →