cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back to annotator catalog
Sensitive file probing signal illustration
Annotator sfp

Sensitive file probing

Requests target commonly sensitive files, configs, backups, or administrative resources.

What This Annotator Watches

This explanation is derived from the live annotator implementation, not hand-waved catalog copy.
Focus
  • Sensitive file paths, configs, backups, and Git metadata
  • Traversal-style file access attempts
  • Direct payload hints such as `/etc/passwd` reads and command-style file parameters
Logic
  • Strong hits target `.env`, SSH keys, OS secrets, CMS configs, and exposed admin artifacts.
  • Traversal and sensitive-file hints are deduplicated so the strongest rule wins.
  • Weak file/path parameters only matter when stronger probing context is present.
How To Read It
This is an opportunistic recon and exposure probe signal. It explains why the request looked like a hunt for accidental leaks.
Catalog Definition
Flags attempts to access files and paths that are commonly sensitive or frequently exposed by mistake (configuration files, environment files, backups, admin panels, hidden resources). This annotator is especially useful for explaining opportunistic scanning behavior. In reports, show targeted resources grouped by category and the observed outcomes (404/403/200) without implying compromise.

10 Most Recent Real Samples

Weekly cached from live annotated access events so the catalog stays fast.
Week
2026W13
Lookback
30 days
Total matched
6062
Latest sample
Mar 01, 2026 • 23:50
Top rules
sfp:file:env · 5 sfp:file:git_metadata · 3 sfp:traversal · 2
Top requester orgs
DigitalOcean, LLC · 4 Contabo GmbH · 2 HOSTGLOBAL.PLUS LTD · 1
Severity mix
40 · 5 24 · 3 34 · 2
Method mix
GET · 8 POST · 2
GET 301 40
Mar 01, 2026 • 23:50
/.env
Probe for environment/secret file (.env)
IP 78.153.140.40 Subnet 78.153.140.0/24 Org HOSTGLOBAL.PLUS LTD Country United Kingdom Rule sfp:file:env
GET 404 24
Mar 01, 2026 • 23:49
/wp-content/themes/.git/config
Probe for Git metadata
IP 113.169.237.215 Subnet 113.169.237.0/24 Org Vietnam Posts and Telecommunications Group Country Vietnam Rule sfp:file:git_metadata
GET 200 40
Mar 01, 2026 • 23:48
/admin/login/?next=/admin/.env.crt
Probe for environment/secret file (.env)
IP 123.17.16.50 Subnet 123.17.16.0/24 Country Vietnam Rule sfp:file:env
GET 302 40
Mar 01, 2026 • 23:48
/admin/.env.crt
Probe for environment/secret file (.env)
IP 123.17.16.50 Subnet 123.17.16.0/24 Country Vietnam Rule sfp:file:env
GET 500 24
Mar 01, 2026 • 23:42
/.git/config
Probe for Git metadata
IP 167.99.182.39 Subnet 167.99.182.0/24 Org DigitalOcean, LLC Country Canada Rule sfp:file:git_metadata
GET 500 40
Mar 01, 2026 • 23:42
/.env
Probe for environment/secret file (.env)
IP 167.99.182.39 Subnet 167.99.182.0/24 Org DigitalOcean, LLC Country Canada Rule sfp:file:env
GET 500 24
Mar 01, 2026 • 23:20
/.git/config
Probe for Git metadata
IP 142.93.143.8 Subnet 142.93.143.0/24 Org DigitalOcean, LLC Country Netherlands Rule sfp:file:git_metadata
GET 500 40
Mar 01, 2026 • 23:20
/.env
Probe for environment/secret file (.env)
IP 142.93.143.8 Subnet 142.93.143.0/24 Org DigitalOcean, LLC Country Netherlands Rule sfp:file:env
POST 400 34
Mar 01, 2026 • 23:05
/cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh
Directory traversal indicator
IP 77.237.243.239 Subnet 77.237.243.0/24 Org Contabo GmbH Country France Rule sfp:traversal
POST 400 34
Mar 01, 2026 • 23:05
/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh
Directory traversal indicator
IP 77.237.243.239 Subnet 77.237.243.0/24 Org Contabo GmbH Country France Rule sfp:traversal