Multiple failed SSH login attempts
Source: 198.51.100.23 · 2026-03-14 02:15:03 UTC
Source IP matches known internal monitoring tool (Nagios health-check scanner, whitelisted since 2025-11-02).
Admin login from new geographic location (London, UK)
Source: 203.0.113.44 · 2026-03-14 08:42:17 UTC
Employee j.chen confirmed international travel via calendar entry; login timing matches expected arrival window.
SQL injection pattern detected in WAF logs
Source: 203.0.113.201 · 2026-03-14 11:07:52 UTC
Source IP has no prior history and is not on any authorized-scanning whitelist. Payload matches UNION-based SQLi against the /api/products?id= parameter. Response timing is consistent with a successful query execution, not a blocked/rejected attempt.
Port scan detected
Source: 192.0.2.15 · 2026-03-14 03:00:11 UTC
Source IP matches this month's scheduled vulnerability scan (Qualys), authorized under change ticket CHG-4471.
Unusual outbound data volume from webserver-03
Source: 10.0.4.12 · 2026-03-14 02:00:44 UTC
Volume spike coincides with the nightly backup job window (02:00-02:45 UTC); consistent with historical baseline for this exact time slot.
Excessive 404 errors from a single source
Source: 192.0.2.88 · 2026-03-14 14:22:09 UTC
User-agent identifies as 'AhrefsBot' (SEO crawler); pattern is consistent with automated site crawling, not directory enumeration.