One attacker, five different techniques, six separate alerts from three defense layers — and zero human intervention up to the block. This is how Aegis correlation turns scattered signals into a single decision.
This concerns a WordPress web application in a shared hosting environment protected by Aegis. The client and exact domain are anonymized — every figure, technique and timeline in this study comes directly from the incident record (WORM ledger), without embellishment.
The attack was not one “loud” event but a series of seemingly unrelated signals scattered across the WAF, SIEM and network layer. Individually, each is easily lost in the noise. The value of a SOC is precisely in joining them into one story — and reacting to it while the attack is still underway.
In just under ten minutes, the same source (31.45.239.xxx) went through five phases in turn:
An automated scanner maps the site structure, looking for known paths and exposed files. The first, quiet signal — not an attack in itself, but the prelude.
Targeted requests to /wp-admin and login paths — the attacker checks whether the interface is open.
The WAF catches an attempt to exploit a known WordPress vulnerability — the payload is blocked at the application layer, but the attacker does not give up.
A series of POST requests to the login — an attempt to break the password with a large number of combinations in a short time.
When the direct breach fails, the attacker switches to resource exhaustion — slowly holding connections open to choke the server.
Each of these phases raised its own alert — six in total, from three different defense layers (WAF, authentication SIEM, network detection). The decisive moment was not any single detection, but correlation:
From the moment correlation confirmed the attack to blocking the source at the firewall, less than a minute passed. After the block, not a single further request from that IP reached the application.
The automatic response is not the end of the story — every decision leaves a trail that can be audited:
That is the difference between “the system blocked something” and “we can show exactly what happened, why and in what order” — whether for an internal audit or NIS2 records.
Aegis connects the signals that individual tools miss — and reacts while the attack is still underway.
Book a call →