Skip to main content

Attack Target Reports

Attack Target Reports

Last verified: 2026-07-08

Attack target reports summarize which usernames and source networks are being hit by failed-login traffic. They help administrators spot targeted accounts, noisy source addresses, and candidates for careful IP access rules.

What the report shows

The report focuses on failed-login signals such as attempted usernames, source previews, counts, and timing windows. It is meant for operational triage, not for publishing raw security logs.

Common uses:

  • Identify usernames attackers keep trying.
  • Find whether one account is being targeted repeatedly.
  • See whether a small set of source networks is driving most failures.
  • Decide whether username hygiene, notifications, brute-force tuning, or IP access rules should be reviewed.

Source interpretation

Treat source IP data as a lead, not proof of a person. One address may represent a VPN exit, office, mobile carrier, proxy, hosting provider, or bot network. A source can also change quickly during distributed attacks.

If the site is behind a proxy, configure trusted proxies before relying on forwarded visitor addresses.

Safe IP-rule prefill

Awthy may help prefill an IP access rule from an attack target report. Review the prefilled values before saving:

  • Prefer monitor mode first.
  • Scope the rule to the smallest surface and subject that makes sense.
  • Avoid broad CIDR ranges unless you know they belong to controlled infrastructure.
  • Confirm the rule will not block administrators or support staff.

Privacy and support boundaries

Do not paste raw full IP addresses, full user agents, request payloads, or customer data into public support channels. Share only the safe summary needed for troubleshooting, such as the affected username pattern, approximate timing, and whether a rule was monitored or enforced.

For account-specific incidents, combine the report with audit log review, session review, password reset, and second-factor checks.