Intrusion Attempt
What It Means
This request is an attempt to gain further unauthorized access to your application.
Why It Matters
Intrusion attempts go beyond simple scanning. They indicate an attacker actively trying to expand their access to your application, potentially by exploiting application logic, accessing internal resources, or escalating privileges.
Common Triggers
Requests that probe for internal application endpoints, attempt to access configuration files, or try to use application features in unintended ways to gain deeper access.
What To Do
These blocks are always legitimate threat detection. They are safe to leave in place, and no action is typically required.
Blocks in this category with a TMP-prefixed code (such as TMP021) are temporary: they expire automatically after about 30 minutes. If a legitimate user triggered one, they can wait out the block, or you can add their IP to your allowlist.