Back to cases

Live public case

Opportunistic scan

Last activity Aug 25, 9:34:17 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not for confirmed compromise. The deterministic detector remains open with a medium-severity scan classification. Verified HTTP summaries show rapid GET probes categorized as PHP/WordPress probes, while the incident aggregates 39 requests across 20 unique probe paths in about 5.4 seconds. The observed responses were redirects or rejections; the available record does not establish command execution or any follow-on host/network consequence.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Observed impact is limited to unsolicited web-path reconnaissance against the target.
  • No exploit execution, persistence, lateral movement, command-and-control, or data theft is established by the cited evidence.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The incident is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not for confirmed compromise. The deterministic detector remains open with a medium-severity scan classification. Verified HTTP summaries show rapid GET probes categorized as PHP/WordPress probes, while the incident aggregates 39 requests across 20 unique probe paths in about 5.4 seconds. The observed responses were redirects or rejections; the available record does not establish command execution or any follow-on host/network consequence.