Live public case
Opportunistic scan
Last activity Aug 27, 1:31:31 PM PDT
Evidence-grounded assessment
Not required
This is a true positive for opportunistic reconnaissance/web-shell enumeration, not a confirmed compromise. The detector derived 39 requests across 20 PHP/WordPress probe paths in about 4.8 seconds, and verified HTTP examples are GETs categorized as php_or_wordpress_probe with distinct path hashes [redacted]. The incident records redirect/rejection-only outcomes for all 39 requests. That supports an attempted discovery scan but does not, by HTTP status alone, prove exploit failure. No process or flow evidence references were cited by this incident, so execution, outbound activity, persistence, or other compromise consequences cannot be assessed from the available evidence.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Observed impact is limited to a rapid inbound path-enumeration burst against the target [redacted].
- No compromise consequence is demonstrated; redirect/rejection outcomes do not by themselves establish exploit success or failure [redacted].
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
This is a true positive for opportunistic reconnaissance/web-shell enumeration, not a confirmed compromise. The detector derived 39 requests across 20 PHP/WordPress probe paths in about 4.8 seconds, and verified HTTP examples are GETs categorized as php_or_wordpress_probe with distinct path hashes [redacted]. The incident records redirect/rejection-only outcomes for all 39 requests. That supports an attempted discovery scan but does not, by HTTP status alone, prove exploit failure. No process or flow evidence references were cited by this incident, so execution, outbound activity, persistence, or other compromise consequences cannot be assessed from the available evidence.