Live public case
Opportunistic scan
Last activity Aug 23, 5:33:30 AM PDT
Evidence-grounded assessment
Not required
The incident is a true positive for opportunistic reconnaissance/web-shell path enumeration, not for successful compromise. The detector recorded 218 requests spanning 110 probe paths in about 23 seconds from one derived source cluster. Verified representative requests were GETs categorized as PHP/WordPress probes and received 301 or 404 outcomes. No cited process or flow evidence was available to establish command execution, outbound activity, persistence, or any other post-request consequence, so impact remains unproven.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Observed activity was limited to rapid HTTP-layer probing and enumeration.
- No successful exploitation or post-request workload consequence was demonstrated by the available cited evidence.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
The incident is a true positive for opportunistic reconnaissance/web-shell path enumeration, not for successful compromise. The detector recorded 218 requests spanning 110 probe paths in about 23 seconds from one derived source cluster. Verified representative requests were GETs categorized as PHP/WordPress probes and received 301 or 404 outcomes. No cited process or flow evidence was available to establish command execution, outbound activity, persistence, or any other post-request consequence, so impact remains unproven.