Live public case
Opportunistic scan
Last activity Aug 26, 1:55:04 AM PDT
Evidence-grounded assessment
Not required
The alert accurately identifies a rapid, opportunistic PHP/WordPress web-shell path-enumeration campaign against target privatekind. The cited HTTP evidence supports real probing activity, while the incident aggregate records 38 requests across 20 probe paths. Observed HTTP outcomes were redirects or rejections, but status codes alone cannot prove that every probe failed. No process or flow evidence was cited by this incident, so there is no verified command execution, persistence, outbound connection, or other compromise consequence.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Confirmed unwanted web-shell path enumeration against the web service; no verified post-exploitation impact in the available cited evidence.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
The alert accurately identifies a rapid, opportunistic PHP/WordPress web-shell path-enumeration campaign against target privatekind. The cited HTTP evidence supports real probing activity, while the incident aggregate records 38 requests across 20 probe paths. Observed HTTP outcomes were redirects or rejections, but status codes alone cannot prove that every probe failed. No process or flow evidence was cited by this incident, so there is no verified command execution, persistence, outbound connection, or other compromise consequence.