Intrusion Attempt

What It Means

This request is an attempt to gain further unauthorized access to your application.

Why It Matters

Intrusion attempts go beyond simple scanning. They indicate an attacker actively trying to expand their access to your application, potentially by exploiting application logic, accessing internal resources, or escalating privileges.

Common Triggers

Requests that probe for internal application endpoints, attempt to access configuration files, or try to use application features in unintended ways to gain deeper access.

What To Do

These blocks are always legitimate threat detection. They are safe to leave in place, and no action is typically required.

Blocks in this category with a TMP-prefixed code (such as TMP021) are temporary: they expire automatically after about 30 minutes. If a legitimate user triggered one, they can wait out the block, or you can add their IP to your allowlist.