Back to cases

Live public case

Opportunistic scan

Last activity Aug 28, 6:12:43 AM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is a true positive for rapid opportunistic enumeration of PHP/WordPress web-shell paths against target privatekind. The detector reports 38 requests over roughly 7.7 seconds and 20 unique probe paths; the verified cited samples are bodyless GET requests categorized as PHP/WordPress probes and received only 301 or 404 responses. This establishes hostile or unauthorized reconnaissance behavior, but not successful exploitation or compromise. No process or flow evidence is cited by the incident, so execution, outbound communication, persistence, or other post-request consequences cannot be determined from the available evidence.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Observed impact is limited to rapid HTTP probing of suspected PHP/WordPress web-shell locations.
  • No successful command execution, persistence, outbound callback, lateral movement, or data loss is established by the available evidence.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The incident is a true positive for rapid opportunistic enumeration of PHP/WordPress web-shell paths against target privatekind. The detector reports 38 requests over roughly 7.7 seconds and 20 unique probe paths; the verified cited samples are bodyless GET requests categorized as PHP/WordPress probes and received only 301 or 404 responses. This establishes hostile or unauthorized reconnaissance behavior, but not successful exploitation or compromise. No process or flow evidence is cited by the incident, so execution, outbound communication, persistence, or other post-request consequences cannot be determined from the available evidence.