Back to cases

Live public case

Opportunistic scan

Last activity Aug 23, 6:13:31 AM PDT

mediumNot required

Evidence-grounded assessment

Not required

This is a true positive for automated reconnaissance/web-shell path enumeration, not a confirmed compromise. The detector aggregated 232 requests across 118 PHP/WordPress probe paths in about 28 seconds, while the cited HTTP outcomes were redirects or rejections (for example, HTTP [redacted], [redacted], [redacted], and [redacted]). HTTP status does not independently prove exploit failure, and the incident provides no cited process or flow identities with which to determine workload execution or outbound network consequences.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Observed impact is rapid inbound enumeration against target privatekind; representative requests received 301 or 404 outcomes [redacted].
  • No workload execution, persistence, lateral movement, outbound callback, or data theft is established by the available incident evidence; process and flow consequence assessment remains unavailable.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      This is a true positive for automated reconnaissance/web-shell path enumeration, not a confirmed compromise. The detector aggregated 232 requests across 118 PHP/WordPress probe paths in about 28 seconds, while the cited HTTP outcomes were redirects or rejections (for example, HTTP [redacted], [redacted], [redacted], and [redacted]). HTTP status does not independently prove exploit failure, and the incident provides no cited process or flow identities with which to determine workload execution or outbound network consequences.