Back to cases

Live public case

Opportunistic scan

Last activity Aug 21, 2:36:09 AM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is a true positive for opportunistic reconnaissance: one derived source cluster rapidly issued GET requests to numerous distinct paths categorized as PHP or WordPress probes against target privatekind. The verified HTTP samples returned 404 responses with the same response-body hash and contained no request bodies. This supports web-shell/path enumeration, but not successful exploitation. HTTP status alone cannot establish exploit failure, and the incident cites no process or flow evidence with which to assess command execution or network consequences.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Confirmed hostile or unauthorized-looking enumeration activity reached the HTTP service.
  • No workload compromise, command execution, persistence, or suspicious outbound connection is demonstrated by the cited evidence.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The incident is a true positive for opportunistic reconnaissance: one derived source cluster rapidly issued GET requests to numerous distinct paths categorized as PHP or WordPress probes against target privatekind. The verified HTTP samples returned 404 responses with the same response-body hash and contained no request bodies. This supports web-shell/path enumeration, but not successful exploitation. HTTP status alone cannot establish exploit failure, and the incident cites no process or flow evidence with which to assess command execution or network consequences.