WordPress attack detection

Attackers find the fake door first.

DecoyNest plants convincing decoys across your site — a fake admin login, a fake vulnerable plugin file, a watched XML-RPC endpoint. Every probe is recorded. Nothing real is touched.

Free and open source · No account required · Works alongside your existing firewall

What an attacker sees
yoursite.com/wp-adm1n/
What you see 3 events
09:14:02 GET /wp-content/plugins/wp-file-manager/readme.txt Vuln scan45.155.205.233 · Go-http-client/1.1
09:14:47 POST /xmlrpc.php → system.multicall ×112 Brute force193.32.162.18 · curl/7.68.0
09:15:31 GET /wp-adm1n/?author=1 Recon141.98.11.72 · Mozilla/5.0 (compatible)

↖ Try the login form. It is a decoy — this is what it records.

3
Decoy endpoints, live on activation
10
Security modules in the free tier
0
Configuration required to start
0
Third-party scripts loaded
How it works

Three steps, then it runs itself.

STEP 01

Activate

Decoys go live the moment you activate the plugin. No setup wizard, no API key, nothing to configure. Your real admin login is untouched.

STEP 02

Attackers take the bait

Bots probe the fake admin path, request readme files from plugins you do not have, and hammer XML-RPC. Real visitors never see any of it.

STEP 03

You read the evidence

Every probe is logged with source IP, request path, payload, and a classification. Export it, or stream it into your SIEM.

What is included

Ten modules. Most of them free.

The free tier is deliberately generous. Every install is a sensor, and a bigger sensor network makes detection better for everyone using it.

Honeypot sensors

Free

Fake admin login, fake plugin files, and XML-RPC monitoring. Logged locally to your own database.

Two-factor auth

Free

TOTP with any authenticator app. Backup codes, per-role enforcement, and a grace period for rollout.

Single sign-on

Free

Microsoft 365, Google Workspace, and GitHub. Verified identities only, scoped to your tenant, and it still goes through two-factor.

Firewall rules

Free

IP allow and block lists with CIDR, country blocking, login rate limiting, and REST API restrictions.

Vulnerability scanner

Free

Checks your core, plugin, and theme versions against known vulnerabilities. CSV export included.

Hardening score

Free

Twenty checks, one score, and a specific fix for each failure. No vague advice.

Audit log

Free

Who created that administrator, who changed the site URL, who edited a theme file — with IP and timestamp.

Security headers

Free

CSP with report-only mode, HSTS, frame options, and referrer policy. Applied through WordPress, not .htaccess.

Encrypted backup

Pro

Scheduled database and file backups, encrypted before they leave the site. Stored locally or in your own Drive, OneDrive or Dropbox — never with us.

Microsoft Sentinel

Pro

Stream honeypot events and audit entries straight into your Log Analytics workspace.

For security teams

Your WordPress estate, in the console you already watch.

No other WordPress security plugin writes to Microsoft Sentinel. DecoyNest sends events through the Azure Monitor Logs Ingestion API into a custom table, so WordPress attacks correlate with your identity and network telemetry instead of sitting in a separate dashboard nobody opens.

  • Custom DecoyNestEvents_CL table with a defined schema
  • Service principal auth, scoped to a single data collection rule
  • Sample analytics rules and a workbook to start from
  • CEF and Syslog export for Splunk, QRadar, and others
Sample analytics rule
// Brute force against WordPress decoys
DecoyNestEvents_CL
| where TimeGenerated > ago(1h)
| where AttackCategory == "brute_force"
| summarize Attempts = count()
    by SourceIPAddress, SiteUrl,
       bin(TimeGenerated, 5m)
| where Attempts > 10
| project TimeGenerated, SourceIPAddress,
          SiteUrl, Attempts
Plain terms

What this is, and what it is not.

It does

  • Detect and record attack attempts through decoys
  • Harden the parts of WordPress that are commonly left open
  • Add modern authentication your organisation already uses
  • Hand the evidence to your SIEM in a usable shape

It does not

  • Claim to block every attack — no plugin can
  • Replace a WAF at the edge, if you run one
  • Load third-party scripts or send your content anywhere
  • Share any data unless you explicitly opt in

Find out what is already knocking.

Most sites are probed within hours of going live. Install DecoyNest and read the log for a week — the results are usually surprising.