Back to cases

Live public case

Opportunistic scan

Last activity Aug 21, 6:38:07 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

This is a true-positive opportunistic web-shell/path-enumeration scan against target privatekind. The detector recorded 39 requests over roughly six seconds, spanning 20 PHP/WordPress probe paths; the inspected bounded HTTP summaries show bodyless GET probes receiving redirects or 404 responses. The available evidence establishes reconnaissance/probing, but not successful exploitation or compromise. No process or flow evidence references are available in this incident, and HTTP status codes alone cannot prove exploit failure.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • The target received rapid automated probing of PHP and WordPress paths.
  • No confirmed command execution, outbound connection, persistence, data access, or other compromise consequence is established by the available cited evidence.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      This is a true-positive opportunistic web-shell/path-enumeration scan against target privatekind. The detector recorded 39 requests over roughly six seconds, spanning 20 PHP/WordPress probe paths; the inspected bounded HTTP summaries show bodyless GET probes receiving redirects or 404 responses. The available evidence establishes reconnaissance/probing, but not successful exploitation or compromise. No process or flow evidence references are available in this incident, and HTTP status codes alone cannot prove exploit failure.