Description: Highlights IPs generating the most suspicious activity against your site in the last 24 hours.
How it works: AegisShield aggregates events by IP (failed logins, lockouts, denied actions) to identify persistent attackers.
How to access / configure:
- WP Admin → AegisShield → Dashboard.
- View “Top Hostile IPs (24h)”.
- Use Login Guard allow/deny tools (Pro) or firewall rules to block repeat offenders.
Recommended setting: Block repeat attacker IPs if they’re stable; avoid blocking CDN/ISP ranges accidentally.
