Live public case
Opportunistic scan
Last activity Aug 20, 1:51:17 AM PDT
Evidence-grounded assessment
Not required
True positive for opportunistic PHP/WordPress web-shell path enumeration, based on a rapid sequence of categorized probe requests from one traffic cluster against target privatekind (for example [redacted], [redacted], [redacted], and [redacted]). The cited HTTP outcomes are redirects or rejections, including 301 and 404 responses; this supports detection of scanning but does not by itself prove exploit failure. No process or flow evidence was cited by the incident, so execution, compromise, or follow-on network activity is not established.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Observed impact is limited to repeated HTTP probing of target privatekind; representative cited requests received 301 or 404 outcomes ([redacted], [redacted], ad3f508e-3a2d-4863-953b-9be3c
- No command execution, persistence, lateral movement, data theft, or request-linked egress is established by the incident's cited evidence; the incident provides HTTP references only.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
True positive for opportunistic PHP/WordPress web-shell path enumeration, based on a rapid sequence of categorized probe requests from one traffic cluster against target privatekind (for example [redacted], [redacted], [redacted], and [redacted]). The cited HTTP outcomes are redirects or rejections, including 301 and 404 responses; this supports detection of scanning but does not by itself prove exploit failure. No process or flow evidence was cited by the incident, so execution, compromise, or follow-on network activity is not established.