Back to cases

Live public case

Opportunistic scan

Last activity Aug 26, 1:58:15 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

This is a true positive for opportunistic reconnaissance: a single derived traffic cluster rapidly enumerated PHP and WordPress web-shell-style paths on target privatekind. The incident records 64 requests across 32 unique probe paths in roughly seven seconds. Verified HTTP samples are GET requests categorized as PHP/WordPress probes and show only redirects or 404 responses. The available evidence establishes scanning, but it does not establish successful exploitation or any downstream workload consequence.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Automated reconnaissance reached the application-facing HTTP service; observed outcomes were redirects or rejection responses, with no demonstrated post-request consequence.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      This is a true positive for opportunistic reconnaissance: a single derived traffic cluster rapidly enumerated PHP and WordPress web-shell-style paths on target privatekind. The incident records 64 requests across 32 unique probe paths in roughly seven seconds. Verified HTTP samples are GET requests categorized as PHP/WordPress probes and show only redirects or 404 responses. The available evidence establishes scanning, but it does not establish successful exploitation or any downstream workload consequence.