Live public case
Opportunistic scan
Last activity Aug 28, 11:46:24 PM PDT
Evidence-grounded assessment
Not required
This is a true positive for rapid opportunistic reconnaissance, not confirmed exploitation. The detector recorded 39 requests across 20 PHP/WordPress probe paths in about 4.3 seconds, and the bounded HTTP summaries show representative GET probes receiving 301 redirects or 404 rejections. The derived detector outcome remains redirect_or_rejection_only. There is no cited process or flow evidence with which to establish command execution, outbound activity, or any request-to-consequence causal edge.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- A short burst of probe traffic was handled by the target and produced redirect/rejection responses (HTTP refs [redacted] and [redacted]).
- No post-request workload or network consequence is verified; the incident cites no process-plane or flow-plane event that can support such a conclusion.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
This is a true positive for rapid opportunistic reconnaissance, not confirmed exploitation. The detector recorded 39 requests across 20 PHP/WordPress probe paths in about 4.3 seconds, and the bounded HTTP summaries show representative GET probes receiving 301 redirects or 404 rejections. The derived detector outcome remains redirect_or_rejection_only. There is no cited process or flow evidence with which to establish command execution, outbound activity, or any request-to-consequence causal edge.