Live public case
Opportunistic scan
Last activity Aug 28, 6:18:43 AM PDT
Evidence-grounded assessment
Not required
The incident is a true positive for opportunistic reconnaissance: the traffic cluster rapidly issued GET requests categorized as PHP or WordPress probes against target privatekind, and the detector aggregated 38 requests spanning 20 unique probe paths. The cited HTTP outcomes were redirects or rejections, so this establishes web-shell path enumeration but not successful exploitation. No process or flow evidence is cited by the incident, leaving execution and downstream network consequences unproven.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Automated enumeration of potential PHP and WordPress web-shell locations against the target.
- No demonstrated command execution, persistence, outbound connection, or other compromise consequence in the available cited evidence.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
The incident is a true positive for opportunistic reconnaissance: the traffic cluster rapidly issued GET requests categorized as PHP or WordPress probes against target privatekind, and the detector aggregated 38 requests spanning 20 unique probe paths. The cited HTTP outcomes were redirects or rejections, so this establishes web-shell path enumeration but not successful exploitation. No process or flow evidence is cited by the incident, leaving execution and downstream network consequences unproven.