WordPress Attack Story: Turn Firewall Events Into an Investigation You Can Act On
Aegisify WAF 1.20.13 builds Attack Story from the canonical local WAF event database. Instead of showing only a stream of blocked requests, it summarizes security events, enforcement actions, targeted routes, responding protection modules, threat families, triggered rules, methods, sources, and recent enforced evidence across a selected investigation window.
Attack Story helps administrators see where pressure is concentrated, which controls responded, and which evidence deserves follow-up without claiming that a log automatically proves attacker identity or intent.
How Attack Story Organizes WAF Evidence
The current implementation builds SQL-backed summaries and rankings from the canonical event table, then lets administrators narrow the story by time window, protection module, and action.
Click a stage to expand
01Choose Window24h to 30d
02FilterModule + action
03SummarizeEvents + enforcement
04RankRoutes, sources, rules
05InspectEnforcement evidence
06RespondUnblock or escalate
Four Visuals Show the Shape of the Attack Pressure
The charts are summaries. Full evidence remains in the event records and enforcement tables.
Security Events vs. Blocks
The Attack Timeline compares total matching security events with blocked activity over the selected window. This helps show whether enforcement pressure appeared as one short burst or persisted across hours or days.
Where Requests Concentrated
A ranked route view identifies endpoints receiving the most matching events. Repeated pressure against login, REST, AJAX, XML-RPC, search, or application paths can guide where tuning or deeper application review should begin.
Which Protection Layers Fired
Attack Story groups logger categories into protection areas such as Core WAF, API & Application, Abuse & Bots, AI Security, DDoS & Rate Control, and Access & Threat Intelligence.
What the Evidence Resembled
Bounded event details are inspected for category, threat type, attack type, family, or reason. This produces a ranked evidence view without treating the label as proof of attacker identity or exploit success.
Move From “Something Was Blocked” to “What Should We Investigate First?”
Rankings help prioritize the parts of the story carrying the most evidence.
Find Concentrated Pressure
Top Sources and Top Targeted Routes expose where the selected event volume is concentrated. One source touching many sensitive paths can represent a different investigation pattern from many sources converging on one endpoint.
See Which Defenses Produced Evidence
Triggered Rules, Threat Families, and Logger Categories show which signatures, policy families, and event types contributed most often. This helps identify whether the story is dominated by managed WAF findings, API controls, DDoS pressure, bot policy, or another layer.
Understand Request and Enforcement Shape
HTTP Method and Action Outcome rankings help distinguish read-heavy probing from repeated write attempts and show whether the response was mainly logging, challenge, throttling, blocking, allowing, or investigation.
One Story Can Contain Evidence From Multiple WAF Layers
The 1.20.13 category catalog makes the investigation broader than managed-rule blocks alone.
Core WAF categories include managed signatures, heuristics, custom rules, endpoint policies, challenge decisions, request integrity, WordPress protection, adaptive defense, and scoped exclusions. API & Application includes REST/AJAX inspection, schema findings, route controls, application monitoring, and Aegisify transport decisions.
Abuse & Bots includes bot classification, bad User-Agent findings, and crawler policy. AI Security can contribute prompt, sensitive-data, output, agency, consumption, provider, and inspection-boundary evidence. DDoS & Rate Control contributes application-layer throttling and temporary-ban activity, while Access & Threat Intelligence covers access rules, block lists, IP, Geo/ASN, and behavioral intelligence.
The Canonical Database Drives Dashboards, Filters, Alerts, and Attack Story
Aegisify uses a canonical local event table plus protected continuity mirrors.
Canonical Database
The database is the authoritative source for dashboard aggregation, event filtering, triage, alerts, and Attack Story. The default database retention is 30 days and can be managed from the log controls.
Protected Flat-File Mirrors
Aegisify maintains protected line-oriented continuity mirrors under the WordPress uploads area and the suite-wide wp-content/aegisify-logs location. The default flat-file retention is seven days.
Operational Events Are Distinguishable
Administration, settings, maintenance, log management, configuration, warning, error, and information categories can be included or separated so operational changes are not confused with incoming threat activity.
Use Attack Story to Decide the Next Security Action
Investigation is valuable when it changes what the team does next.
See Which Routes, Sources, Rules, and Protection Layers Are Driving the Story
Use Attack Story with the WAF event explorer to turn enforcement evidence into a repeatable investigation workflow.
Common Questions About WAF Investigation
Does Attack Story prove who the attacker is?
No. IP addresses, User-Agents, network attributes, and request patterns can be shared or spoofed. Attack Story organizes local WAF evidence and enforcement context; it should not be presented as definitive identity attribution.
Does it only show blocked requests?
No. The story can summarize matching security events and filter by multiple actions. It separately highlights recent enforcement evidence such as block, challenge, and rate-limit outcomes.
Are rankings built from only the current event page?
No. The current implementation generates rankings through SQL aggregation across the selected story window rather than a capped Event Explorer page sample.
Can an administrator respond to a false positive?
Yes. Blocked Decision Operations support reviewing recent blocks and creating a narrow supported allow override. Administrators should validate the application behavior before adding an exception.
How can Aegisify AI help?
Ask about Aegisify or WordPress: errors, plugins, security, SEO, compatibility, troubleshooting, comparisons, or launch a free website scan.
