Back to cases

Live public case

Opportunistic scan

Last activity Aug 28, 8:30:20 AM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is a true positive for rapid automated PHP/WordPress web-shell path enumeration, not for confirmed compromise. The detector grouped 39 requests across 20 unique probe paths in approximately 4.27 seconds. Retrieved representative requests are categorized as php_or_wordpress_probe and returned only 301 or 404 responses. Those status codes do not by themselves prove exploit failure, but the available evidence contains no process or flow references with which to establish execution, outbound activity, persistence, or data access.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • No confirmed compromise impact can be established from the available HTTP-only evidence; observed consequences are limited to probe traffic and redirect/rejection responses.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The incident is a true positive for rapid automated PHP/WordPress web-shell path enumeration, not for confirmed compromise. The detector grouped 39 requests across 20 unique probe paths in approximately 4.27 seconds. Retrieved representative requests are categorized as php_or_wordpress_probe and returned only 301 or 404 responses. Those status codes do not by themselves prove exploit failure, but the available evidence contains no process or flow references with which to establish execution, outbound activity, persistence, or data access.