Back to cases

Live public case

Opportunistic scan

Last activity Aug 26, 10:37:25 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

This is a true positive for opportunistic reconnaissance: a rapid burst enumerated PHP and WordPress web-shell-style paths. The available HTTP evidence shows redirects and rejections, so the observed incident is scanning rather than a demonstrated compromise. No cited process or flow evidence was available to establish execution or outbound network consequences.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Confirmed hostile or unauthorized-looking web-path enumeration against the target.
  • No workload execution, persistence, outbound connection, or data-loss consequence is established by the available evidence.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      This is a true positive for opportunistic reconnaissance: a rapid burst enumerated PHP and WordPress web-shell-style paths. The available HTTP evidence shows redirects and rejections, so the observed incident is scanning rather than a demonstrated compromise. No cited process or flow evidence was available to establish execution or outbound network consequences.