Back to cases

Live public case

Opportunistic scan

Last activity Aug 29, 7:22:19 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

This is a true positive for opportunistic reconnaissance: the detector aggregated 39 rapid GET requests across 20 PHP/WordPress probe paths from one derived traffic cluster. The verified HTTP summaries show capture-complete probe requests receiving redirects or rejections, including 301 and 404 responses. The evidence supports web-shell path enumeration, but not successful exploitation or compromise. No process or flow evidence is cited by this incident, and HTTP status alone cannot establish exploit failure, so execution and network consequences remain unproven rather than ruled out.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Observed impact is limited to rapid inbound PHP/WordPress path probing and associated gateway/application request handling; no execution or outbound-network consequence is demonstrated.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      This is a true positive for opportunistic reconnaissance: the detector aggregated 39 rapid GET requests across 20 PHP/WordPress probe paths from one derived traffic cluster. The verified HTTP summaries show capture-complete probe requests receiving redirects or rejections, including 301 and 404 responses. The evidence supports web-shell path enumeration, but not successful exploitation or compromise. No process or flow evidence is cited by this incident, and HTTP status alone cannot establish exploit failure, so execution and network consequences remain unproven rather than ruled out.