31100 ^4 Web server 400 error code. attack,pci_dss_6.5,pci_dss_11.4,gdpr_IV_35.7.d,nist_800_53_SA.11,nist_800_53_SI.4,tsc_CC6.6,tsc_CC7.1,tsc_CC8.1,tsc_CC6.1,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, 31100 ^50 Web server 500 error code (server error). 31120 ^500 Web server 500 error code (Internal Error). system_error, 31101 Multiple web server 400 error codes from same source ip. T1595.002 web_scan,recon,pci_dss_6.5,pci_dss_11.4,gdpr_IV_35.7.d,nist_800_53_SA.11,nist_800_53_SI.4,tsc_CC6.6,tsc_CC7.1,tsc_CC8.1,tsc_CC6.1,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, 5500 session opened for user PAM: Login session opened. T1078 authentication_success,pci_dss_10.2.5,gpg13_7.8,gpg13_7.9,gdpr_IV_32.2,hipaa_164.312.b,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, 5500 session closed for user PAM: Login session closed. pci_dss_10.2.5,gpg13_7.8,gpg13_7.9,gdpr_IV_32.2,hipaa_164.312.b,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, 23501 no_full_log Solved The $(vulnerability.cve) that affected $(vulnerability.package.name) was solved due to an update in the agent or feed. 23501 no_full_log Active Low $(vulnerability.cve) affects $(vulnerability.package.name) 23501 no_full_log Active Medium|Untriaged $(vulnerability.cve) affects $(vulnerability.package.name) 23501 no_full_log Active High $(vulnerability.cve) affects $(vulnerability.package.name) 23501 no_full_log Active Critical $(vulnerability.cve) affects $(vulnerability.package.name) json no_full_log Clear Vulnerabilities cleared 19006 ^failed no_full_log $(sca.policy): $(sca.check.title) 2900 ^status installed$ New dpkg (Debian Package) installed. config_changed,pci_dss_10.6.1,pci_dss_10.2.7,gpg13_4.10,gdpr_IV_35.7.d,hipaa_164.312.b,nist_800_53_AU.6,nist_800_53_AU.14,tsc_CC7.2,tsc_CC7.3,tsc_CC6.8,tsc_CC8.1, 2900 ^status half-configured$ Dpkg (Debian Package) half configured. config_changed,pci_dss_10.6.1,pci_dss_10.2.7,gpg13_4.10,gdpr_IV_35.7.d,hipaa_164.312.b,nist_800_53_AU.6,nist_800_53_AU.14,tsc_CC7.2,tsc_CC7.3,tsc_CC6.8,tsc_CC8.1, ossec syscheck_integrity_changed Integrity checksum changed. T1565.001 syscheck,syscheck_entry_modified,syscheck_file,pci_dss_11.5,gpg13_4.11,gdpr_II_5.1.f,hipaa_164.312.c.1,hipaa_164.312.c.2,nist_800_53_SI.7,tsc_PI1.4,tsc_PI1.5,tsc_CC6.1,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, more authentication failures;|REPEATED login failures syslog: User missed the password more than one time T1110 authentication_failed,pci_dss_10.2.4,pci_dss_10.2.5,gpg13_7.8,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.b,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.1,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, 5503 PAM: Multiple failed logins in a small period of time. T1110 authentication_failures,pci_dss_10.2.4,pci_dss_10.2.5,pci_dss_11.4,gpg13_7.8,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.b,nist_800_53_AU.14,nist_800_53_AC.7,nist_800_53_SI.4,tsc_CC6.1,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, 31509 CMS (WordPress or Joomla) brute force attempt. T1110 pci_dss_6.5,pci_dss_11.4,pci_dss_6.5.10,pci_dss_10.2.4,pci_dss_10.2.5,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.b,nist_800_53_SA.11,nist_800_53_SI.4,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.6,tsc_CC7.1,tsc_CC8.1,tsc_CC6.1,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3, 40700 status=1/FAILURE Systemd: Service exited due to a failure. gpg13_4.3,gdpr_IV_35.7.d, syscheck wp-config\.php$ Cloudron: wp-config.php changed - #823-pattern persistence vector (backdoor was injected here). Verify the change is sanctioned. T1505.003 syscheck uploads/.*\.php$ Cloudron: PHP file in uploads dir - #823-pattern webshell staging (41 webshells found there 2026-09-06). T1505.003 5710 100.68.10.17 Invalid user tsys-ucs-02\$ UCS machine-account SSH probe (tsys-ucs-02$ from tsys-ucs-02 every 20min, UCS domain artifact CR 24 - dispositioned L3). 31100, 31101, 31103, 31104, 31106, 31108, 31109, 31110, 31115, 31120, 31121, 31122, 31123 uploads/.*\.php Cloudron: web request to PHP inside uploads - possible webshell access (#823 pattern). T1505.003