Back to cases

Live public case

Reconnaissance

Last activity Aug 19, 4:50:05 AM PDT

mediumNot requiredResolved · Authorized test

Evidence-grounded assessment

Not required

Likely true positive for automated, unauthenticated web-surface reconnaissance against target privatekind. The aggregate volume, near one-to-one request/path ratio, rapid timing, varied route categories, and representative PHP/WordPress probing strongly support route enumeration rather than ordinary browsing. Authorization cannot be established, so the activity could still be an approved scanner. The incident cites no process or flow evidence establishing exploitation or downstream workload consequences.

Shared case lifecycle

Resolved · Authorized test

This read-only state comes from the same canonical workflow as the private operator console. Notes and append-only action history remain private.

Observed impact

  • Potential discovery of exposed application routes and response behavior.
  • Observed impact is limited to reconnaissance traffic; no verified execution, persistence, lateral movement, command-and-control, or data loss.

Recommended actions

    Attack timeline

    1 incident threads

    Resolution changes operator work, not the preserved attack evidence below.

    1. 1
      Reconnaissanceopen

      Likely true positive for automated, unauthenticated web-surface reconnaissance against target privatekind. The aggregate volume, near one-to-one request/path ratio, rapid timing, varied route categories, and representative PHP/WordPress probing strongly support route enumeration rather than ordinary browsing. Authorization cannot be established, so the activity could still be an approved scanner. The incident cites no process or flow evidence establishing exploitation or downstream workload consequences.