Back to cases

Live public case

Opportunistic scan

Last activity Aug 27, 2:16:16 AM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is a true positive for opportunistic reconnaissance: a single derived traffic cluster rapidly issued GET requests categorized as PHP/WordPress probes across differing path hashes. The cited HTTP samples received only 301 redirects or 404 responses. This establishes hostile-style web-shell path enumeration, but not successful exploitation or compromise. No process or flow evidence was cited by the incident, so workload-side execution, outbound activity, persistence, or other consequences cannot be determined from the available evidence.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Exposure to rapid web-shell path probing; no successful exploitation or workload consequence is established by the cited evidence.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The incident is a true positive for opportunistic reconnaissance: a single derived traffic cluster rapidly issued GET requests categorized as PHP/WordPress probes across differing path hashes. The cited HTTP samples received only 301 redirects or 404 responses. This establishes hostile-style web-shell path enumeration, but not successful exploitation or compromise. No process or flow evidence was cited by the incident, so workload-side execution, outbound activity, persistence, or other consequences cannot be determined from the available evidence.