Live public case
Opportunistic scan
Last activity Aug 22, 12:23:57 PM PDT
Evidence-grounded assessment
Not required
True positive for opportunistic PHP/WordPress web-shell path enumeration, not for successful exploitation. The HTTP evidence shows rapid GET probes from one derived source cluster, categorized as PHP/WordPress probes, including the first and last cited events [http:[redacted]; http:[redacted]]. The detector aggregated 38 requests over 20 unique probe paths and recorded only redirects or rejections across the cited set. No process or flow evidence is cited by this incident, so execution, outbound connectivity, persistence, or other compromise consequences are not established.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Attempted discovery of exposed PHP/WordPress web-shell resources; the observed HTTP outcome was redirect or rejection only [http:[redacted]; http:[redacted]; http:7fff9a16-9749-4e7b-a4c0-8
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
True positive for opportunistic PHP/WordPress web-shell path enumeration, not for successful exploitation. The HTTP evidence shows rapid GET probes from one derived source cluster, categorized as PHP/WordPress probes, including the first and last cited events [http:[redacted]; http:[redacted]]. The detector aggregated 38 requests over 20 unique probe paths and recorded only redirects or rejections across the cited set. No process or flow evidence is cited by this incident, so execution, outbound connectivity, persistence, or other compromise consequences are not established.