Back to cases

Live public case

Opportunistic scan

Last activity Aug 30, 1:47:25 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

The alert accurately identifies a rapid, opportunistic enumeration campaign against PHP/WordPress web-shell-style paths. The verified HTTP samples are bodyless GET probes assigned to the php_or_wordpress_probe category, use multiple distinct path hashes, and span roughly 5.34 seconds. Sampled outcomes are redirects or not-found responses; they establish reconnaissance but not exploitation or compromise. No process- or flow-plane event references are available in this incident to assess downstream execution or network consequences.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Confirmed exposure to a rapid web-shell path enumeration campaign.
  • No confirmed command execution, persistence, outbound connection, data access, or other compromise consequence in the available evidence.
  • Observed HTTP handling was limited to redirects and not-found responses in the verified samples.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The alert accurately identifies a rapid, opportunistic enumeration campaign against PHP/WordPress web-shell-style paths. The verified HTTP samples are bodyless GET probes assigned to the php_or_wordpress_probe category, use multiple distinct path hashes, and span roughly 5.34 seconds. Sampled outcomes are redirects or not-found responses; they establish reconnaissance but not exploitation or compromise. No process- or flow-plane event references are available in this incident to assess downstream execution or network consequences.