Live public case
Opportunistic scan
Last activity Aug 31, 7:46:43 PM PDT
Evidence-grounded assessment
Not required
This is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not for successful exploitation. The deterministic detector recorded 41 requests against 20 probe paths in roughly 4.7 seconds. The retained HTTP summaries consistently classify the requests as PHP/WordPress probes from one traffic cluster to target privatekind and show only 301 redirects or 404 responses. No cited process or flow evidence is available to establish command execution, persistence, outbound activity, or other compromise consequences.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- The observed activity attempted to discover exposed PHP or WordPress web-shell endpoints.
- No successful exploitation or adverse workload consequence is demonstrated by the available evidence.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
This is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not for successful exploitation. The deterministic detector recorded 41 requests against 20 probe paths in roughly 4.7 seconds. The retained HTTP summaries consistently classify the requests as PHP/WordPress probes from one traffic cluster to target privatekind and show only 301 redirects or 404 responses. No cited process or flow evidence is available to establish command execution, persistence, outbound activity, or other compromise consequences.