Live public case
Opportunistic scan
Last activity Aug 19, 5:50:16 AM PDT
Evidence-grounded assessment
Not required
This is a true positive for rapid, opportunistic PHP/WordPress web-shell path enumeration, not a demonstrated compromise. The incident aggregates 331 requests across 167 unique probe paths from one derived source cluster over approximately 12 seconds, and the bounded HTTP evidence confirms GET requests categorized as PHP/WordPress probes [[redacted], [redacted], [redacted], [redacted]]. The incident reports redirect/rejection-only outcomes for all 331 requests, with cited summaries showing 301 or 404 responses [[redacted], [redacted], [redacted], [redacted]]. No process- or flow-plane evidence is cited, so the available evidence does not establish command execution, outbound activity, persistence, or other post-exploitation impact.
Shared case lifecycle
Resolved · Authorized test
This read-only state comes from the same canonical workflow as the private operator console. Notes and append-only action history remain private.
Observed impact
- The target received 331 rapid web-shell-path probes spanning 167 unique paths [[redacted], [redacted], [redacted], [redacted], 1147abb7-
- [redacted], [redacted], [redacted], [redacted], [redacted], [redacted], 3ca390a0-48e
- The observed HTTP consequence was limited to redirects or rejections; no successful exploitation consequence is demonstrated by the available evidence [[redacted], [redacted], 3ca390a0-48e
Recommended actions
Attack timeline
1 incident threads
Resolution changes operator work, not the preserved attack evidence below.
- 1Opportunistic scanopen
This is a true positive for rapid, opportunistic PHP/WordPress web-shell path enumeration, not a demonstrated compromise. The incident aggregates 331 requests across 167 unique probe paths from one derived source cluster over approximately 12 seconds, and the bounded HTTP evidence confirms GET requests categorized as PHP/WordPress probes [[redacted], [redacted], [redacted], [redacted]]. The incident reports redirect/rejection-only outcomes for all 331 requests, with cited summaries showing 301 or 404 responses [[redacted], [redacted], [redacted], [redacted]]. No process- or flow-plane evidence is cited, so the available evidence does not establish command execution, outbound activity, persistence, or other post-exploitation impact.