Storm-3168 (JADEPUFFER) probing of sensitive Azure App Service endpoints

This rule detects reconnaissance activity targeting Azure App Service instances, specifically looking for attempts to access web-shell-like files, WordPress administration paths, PHP-CGI endpoints, or LangFlow code validation paths. It identifies potential Storm-3168 actor infrastructure through known IOCs or through patterns of high-volume, path-diverse HTTP requests that deviate from typical noise, helping to distinguish targeted probing from common internet background scanning.