Back to cases

Live public case

Opportunistic scan

Last activity Sep 1, 10:21:03 AM PDT

mediumNot required

Evidence-grounded assessment

Not required

This is a true-positive opportunistic reconnaissance event: the source traffic cluster rapidly issued repeated GET requests categorized as PHP/WordPress probes against target privatekind. The detector aggregate records 37 requests across 20 unique probe paths in about 4.4 seconds. Available HTTP evidence shows redirect/rejection outcomes (301 and 404), with no server-generated command output in the inspected summaries. The evidence supports web-shell path enumeration, but not successful exploitation or compromise.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Observed impact is limited to hostile scanning traffic and associated request handling; no verified workload execution, outbound connection, persistence, lateral movement, or data loss is established.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      This is a true-positive opportunistic reconnaissance event: the source traffic cluster rapidly issued repeated GET requests categorized as PHP/WordPress probes against target privatekind. The detector aggregate records 37 requests across 20 unique probe paths in about 4.4 seconds. Available HTTP evidence shows redirect/rejection outcomes (301 and 404), with no server-generated command output in the inspected summaries. The evidence supports web-shell path enumeration, but not successful exploitation or compromise.