31100
^4
Web server 400 error code.
attack,pci_dss_6.5,pci_dss_11.4,gdpr_IV_35.7.d,nist_800_53_SA.11,nist_800_53_SI.4,tsc_CC6.6,tsc_CC7.1,tsc_CC8.1,tsc_CC6.1,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3,
31100
^50
Web server 500 error code (server error).
31120
^500
Web server 500 error code (Internal Error).
system_error,
31101
Multiple web server 400 error codes
from same source ip.
T1595.002
web_scan,recon,pci_dss_6.5,pci_dss_11.4,gdpr_IV_35.7.d,nist_800_53_SA.11,nist_800_53_SI.4,tsc_CC6.6,tsc_CC7.1,tsc_CC8.1,tsc_CC6.1,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3,
5500
session opened for user
PAM: Login session opened.
T1078
authentication_success,pci_dss_10.2.5,gpg13_7.8,gpg13_7.9,gdpr_IV_32.2,hipaa_164.312.b,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3,
5500
session closed for user
PAM: Login session closed.
pci_dss_10.2.5,gpg13_7.8,gpg13_7.9,gdpr_IV_32.2,hipaa_164.312.b,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3,
23501
no_full_log
Solved
The $(vulnerability.cve) that affected $(vulnerability.package.name) was solved due to an update in the agent or feed.
23501
no_full_log
Active
Low
$(vulnerability.cve) affects $(vulnerability.package.name)
23501
no_full_log
Active
Medium|Untriaged
$(vulnerability.cve) affects $(vulnerability.package.name)
23501
no_full_log
Active
High
$(vulnerability.cve) affects $(vulnerability.package.name)
23501
no_full_log
Active
Critical
$(vulnerability.cve) affects $(vulnerability.package.name)
json
no_full_log
Clear
Vulnerabilities cleared
19006
^failed
no_full_log
$(sca.policy): $(sca.check.title)
2900
^status installed$
New dpkg (Debian Package) installed.
config_changed,pci_dss_10.6.1,pci_dss_10.2.7,gpg13_4.10,gdpr_IV_35.7.d,hipaa_164.312.b,nist_800_53_AU.6,nist_800_53_AU.14,tsc_CC7.2,tsc_CC7.3,tsc_CC6.8,tsc_CC8.1,
2900
^status half-configured$
Dpkg (Debian Package) half configured.
config_changed,pci_dss_10.6.1,pci_dss_10.2.7,gpg13_4.10,gdpr_IV_35.7.d,hipaa_164.312.b,nist_800_53_AU.6,nist_800_53_AU.14,tsc_CC7.2,tsc_CC7.3,tsc_CC6.8,tsc_CC8.1,
ossec
syscheck_integrity_changed
Integrity checksum changed.
T1565.001
syscheck,syscheck_entry_modified,syscheck_file,pci_dss_11.5,gpg13_4.11,gdpr_II_5.1.f,hipaa_164.312.c.1,hipaa_164.312.c.2,nist_800_53_SI.7,tsc_PI1.4,tsc_PI1.5,tsc_CC6.1,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3,
more authentication failures;|REPEATED login failures
syslog: User missed the password more than one time
T1110
authentication_failed,pci_dss_10.2.4,pci_dss_10.2.5,gpg13_7.8,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.b,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.1,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3,
5503
PAM: Multiple failed logins in a small period of time.
T1110
authentication_failures,pci_dss_10.2.4,pci_dss_10.2.5,pci_dss_11.4,gpg13_7.8,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.b,nist_800_53_AU.14,nist_800_53_AC.7,nist_800_53_SI.4,tsc_CC6.1,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3,
31509
CMS (WordPress or Joomla) brute force attempt.
T1110
pci_dss_6.5,pci_dss_11.4,pci_dss_6.5.10,pci_dss_10.2.4,pci_dss_10.2.5,gdpr_IV_35.7.d,gdpr_IV_32.2,hipaa_164.312.b,nist_800_53_SA.11,nist_800_53_SI.4,nist_800_53_AU.14,nist_800_53_AC.7,tsc_CC6.6,tsc_CC7.1,tsc_CC8.1,tsc_CC6.1,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3,
40700
status=1/FAILURE
Systemd: Service exited due to a failure.
gpg13_4.3,gdpr_IV_35.7.d,
syscheck
wp-config\.php$
Cloudron: wp-config.php changed - #823-pattern persistence vector (backdoor was injected here). Verify the change is sanctioned.
T1505.003
syscheck
uploads/.*\.php$
Cloudron: PHP file in uploads dir - #823-pattern webshell staging (41 webshells found there 2026-09-06).
T1505.003
31100, 31101, 31103, 31104, 31106, 31108, 31109, 31110, 31115, 31120, 31121, 31122, 31123
uploads/.*\.php
Cloudron: web request to PHP inside uploads - possible webshell access (#823 pattern).
T1505.003