Since yesterday, SANS ISC's distributed sensors have recorded a small number of scans for wordfence-waf.php. That file is part of Wordfence, a security plugin for WordPress, and is generated when the plugin is installed on a site.

The scans are notable because they specifically probe for a file that signals Wordfence is present. Automated tools can use that signal to identify WordPress sites running the plugin's web application firewall. SANS ISC describes the total volume as small.

The diary entry does not mention any exploitation attempts, only the scans themselves. Site administrators who see similar requests in their logs may want to review them, but SANS ISC has not linked the pattern to a specific attack campaign.