Back to cases

Live public case

Opportunistic scan

Last activity Aug 30, 1:47:34 AM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not for successful exploitation. The detector aggregated 39 requests across 20 probe paths in roughly 4.3 seconds. Verified HTTP summaries identify sampled requests as GETs in the php_or_wordpress_probe category; the first returned a 301 with an empty response body and the next returned a 404. The incident's cited HTTP evidence records only redirects or rejections, with no observed exploit consequence. No process or flow evidence references were available in this incident, so execution, outbound activity, and compromise cannot be determined from those planes.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Observed impact is limited to rapid inbound reconnaissance and web-shell path probing; successful exploitation or workload compromise is not established.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The incident is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not for successful exploitation. The detector aggregated 39 requests across 20 probe paths in roughly 4.3 seconds. Verified HTTP summaries identify sampled requests as GETs in the php_or_wordpress_probe category; the first returned a 301 with an empty response body and the next returned a 404. The incident's cited HTTP evidence records only redirects or rejections, with no observed exploit consequence. No process or flow evidence references were available in this incident, so execution, outbound activity, and compromise cannot be determined from those planes.