Back to cases

Live public case

Opportunistic scan

Last activity Aug 21, 9:31:21 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

This is a true positive for opportunistic reconnaissance: the cited traffic cluster rapidly enumerated PHP/WordPress probe paths on target privatekind. The aggregate signal records 38 requests across 20 unique probe paths, with all 38 receiving redirect or rejection outcomes, supported by HTTP evidence [redacted] through [redacted]. Representative capture-complete summaries show GET probes returning either an empty 301 or a 404 ([redacted]; [redacted]). This verifies the scan attempt, but does not establish successful exploitation or workload compromise. No process or flow references were cited by the incident, so consequence telemetry could not be evaluated.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Confirmed impact is limited to rapid inbound probe traffic against target privatekind; the cited HTTP evidence establishes scanning but not successful execution or compromise ([redacted]; e15ff174-7aa1-4d13-a44d-72
  • No persistence, lateral movement, command-and-control, data theft, or host escape is established by the available incident evidence.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      This is a true positive for opportunistic reconnaissance: the cited traffic cluster rapidly enumerated PHP/WordPress probe paths on target privatekind. The aggregate signal records 38 requests across 20 unique probe paths, with all 38 receiving redirect or rejection outcomes, supported by HTTP evidence [redacted] through [redacted]. Representative capture-complete summaries show GET probes returning either an empty 301 or a 404 ([redacted]; [redacted]). This verifies the scan attempt, but does not establish successful exploitation or workload compromise. No process or flow references were cited by the incident, so consequence telemetry could not be evaluated.