Live public case
Opportunistic scan
Last activity Aug 26, 1:54:40 PM PDT
Evidence-grounded assessment
Not required
High-confidence true positive for rapid opportunistic PHP/WordPress web-shell path enumeration against target privatekind. Verified HTTP summaries show repeated GET requests categorized as php_or_wordpress_probe, with distinct path hashes, from one derived source cluster over roughly 4.4 seconds. The incident detector reports 38 requests across 20 unique probe paths. Observed HTTP outcomes were redirects or rejections, but status codes alone do not prove exploit failure. No process or flow evidence is cited by this incident, so successful execution or follow-on network activity is neither demonstrated nor conclusively excluded.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Confirmed PHP/WordPress web-shell path enumeration reached the HTTP service.
- No demonstrated command execution, persistence, outbound connection, lateral movement, or data loss in the available cited evidence.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
High-confidence true positive for rapid opportunistic PHP/WordPress web-shell path enumeration against target privatekind. Verified HTTP summaries show repeated GET requests categorized as php_or_wordpress_probe, with distinct path hashes, from one derived source cluster over roughly 4.4 seconds. The incident detector reports 38 requests across 20 unique probe paths. Observed HTTP outcomes were redirects or rejections, but status codes alone do not prove exploit failure. No process or flow evidence is cited by this incident, so successful execution or follow-on network activity is neither demonstrated nor conclusively excluded.