Back to cases

Live public case

Opportunistic scan

Last activity Aug 25, 12:30:30 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is a true positive for opportunistic reconnaissance: one derived traffic cluster rapidly issued GET requests categorized as PHP/WordPress probes against target privatekind. The detector reports 39 requests spanning 20 unique probe paths in about 4.5 seconds. The cited HTTP outcomes are redirects or rejections, with no evidence establishing web-shell access or command execution. This verdict confirms the scan activity, not a compromise.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Attempted enumeration of potentially exposed PHP or WordPress web-shell endpoints.
  • No confirmed command execution, persistence, outbound connection, or other workload consequence in the available evidence.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The incident is a true positive for opportunistic reconnaissance: one derived traffic cluster rapidly issued GET requests categorized as PHP/WordPress probes against target privatekind. The detector reports 39 requests spanning 20 unique probe paths in about 4.5 seconds. The cited HTTP outcomes are redirects or rejections, with no evidence establishing web-shell access or command execution. This verdict confirms the scan activity, not a compromise.