
The paths matter more than the scan count
Public-facing applications receive automated scans every day. The arrival of another scanner is rarely news. What deserves a security leader’s attention is what it asks the application to reveal.

Blocked requests for three selected tool categories.
We examined SiteWALL data for three scanning tools, ffuf, Nmap and ZGrab. Other tools reached our protected applications during the same period. We picked these three because their requests show different ways of hunting for exposure. They look for hidden paths, identifiable services and endpoints associated with specific applications.
The records show 39,906 requests bearing an ffuf user agent, 20,513 classified as Nmap, and 6,402 across the listed ZGrab user agents. SiteWALL blocked all the requests covered here. These are separate figures for the selected tools, not a count of distinct operators or the whole of the scanning we saw.
Ffuf, searching for hidden paths
Ffuf is a web fuzzer. It cycles through part of a URL to test whether candidate files, directories or endpoints exist.
One source IP accounted for 30,004 of the ffuf requests, roughly three quarters of the ffuf total in these records. Separately, the ffuf path export includes /_admin, /_backup, /_old and /_dev, along with filenames such as README, VERSION and Makefile. The exports do not link those individual paths to that source IP.
These are plausible places to look for an admin interface, forgotten content or clues about how an application was built. The path export does not show how all 39,906 ffuf requests were spread across URLs, so the examples should not be read as the bulk of that traffic. One source IP does not tell us who ran the scanner, either.
What the records do show is sustained scanning from a single address. SiteWALL blocked the ffuf requests covered here.
Nmap, learning what a service might be
Nmap is a network discovery and security assessment tool. Its scripting engine can send HTTP requests to identify services and see how they respond.
The Nmap records include paths such as /HNAP1, /sdk and JSP pages associated with Hadoop services, among them /jobtracker.jsp and /dfshealth.jsp. A scanner requests paths like these to check whether a familiar product might be present. The request alone does not mean the product was installed.
Other requests begin nmaplowercheck. Nmap generates these paths to see how a server answers a URL that should not exist. The result helps it judge whether other apparent findings are real.
More than 20,400 requests identified themselves as the Nmap Scripting Engine. That label is self-reported and could be forged, so we read it alongside the requested paths rather than treating it as proof on its own. SiteWALL blocked these requests too.
ZGrab, checking recognisable application endpoints
ZGrab is an application layer scanner that gathers information about services exposed to the internet. In these records, its requests include paths associated with specific applications, management interfaces and known exposure patterns.
|
Requested path |
What a scanner may be checking |
|
|
A SAP NetWeaver Visual Composer endpoint associated with a disclosed 2025 vulnerability |
|
OWA, ECP and Autodiscover paths |
Microsoft Exchange interfaces and known probing patterns |
|
|
A Spring Boot health endpoint |
|
|
A potentially exposed environment configuration file |
|
|
Apache Tomcat management interfaces |
|
|
A WordPress users API route |

Examples drawn from the ffuf and ZGrab path exports. Potential exposures are illustrative; the requests shown were blocked by SiteWALL.
These paths also explain what a successful discovery might offer. An exposed /.env file could reveal configuration secrets. An accessible backup or development directory could contain forgotten material. An open management interface could offer a route into a service. The SiteWALL records show attempts to find such resources, not that the scanners reached them.
A path’s frequency tells us that scanners went looking for it, not that the corresponding software was present or vulnerable. After the site root, the most requested ZGrab path was /developmentserver/metadatauploader, with 535 requests. That shows interest in an endpoint associated with a known SAP vulnerability. It does not mean SAP software was running, vulnerable or breached.
The records also include 112 requests whose client identified itself as llm-scan-zgrab2/0.1. That label is self-reported, not proof that AI drove the activity. SiteWALL blocked these requests as well.
Turning reconnaissance into a security decision
These tools have legitimate uses in authorised testing and internet research. Their names do not tell us who sent a request or why. Even a probe for a path linked to a known flaw is not, on its own, evidence that the flaw exists on the target.
The value for a defender comes from connecting each request to application inventory and protection outcomes. Which application was probed? Is the technology being sought actually deployed? How was the request handled? Did subsequent traffic shift from discovery to an attempt at exploitation?
The stakes of an actual weakness are clear. Verizon’s 2026 Data Breach Investigations Report found that vulnerability exploitation was the initial access vector in 31% of breaches in its reporting dataset, up from 20% in the previous report. For the first time in the DBIR’s history, it overtook credential abuse as the most common initial access vector.
That Verizon finding sits apart from the SiteWALL data. The requests covered here were blocked. These records do not establish that an exploit succeeded.
For a CISO, the sharper question is not how much scanning arrived. It is what the scanners were looking for, whether those resources could have been exposed, and whether the controls stopped the requests.
The ffuf, Nmap and ZGrab records show different forms of discovery directed at protected applications. SiteWALL blocked every request covered in this analysis. Reconnaissance is a running readout of what outsiders are testing for. The task is to use that information to check the application inventory, confirm the controls worked and ensure sensitive resources are not exposed when those paths are probed.



