Storm-1175 Medusa Ransomware Pre-Exploitation CVE Path Scanning

Detects anomalous external scanning activity against internal web applications by monitoring for multiple requests to sensitive URI paths associated with vulnerability exploitation (e.g., cgi-bin, admin-ajax.php, .env, or command execution endpoints) originating from external IP addresses to internal network space.