Live public case
Opportunistic scan
Last activity Aug 27, 7:11:50 PM PDT
Evidence-grounded assessment
Not required
The incident is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not a confirmed compromise. The detector aggregated 39 requests across 20 probe paths in roughly 4.3 seconds, and the reviewed immutable HTTP records consistently classify the requests as php_or_wordpress_probe traffic from the same source cluster to target privatekind [http:[redacted], http:[redacted], http:[redacted]]. Sampled responses were redirects or rejections (301/404), with no request bodies [same references]. This supports a reconnaissance/enumeration verdict. It does not establish exploitation, command execution, persistence, or outbound activity; no process or flow evidence was cited by the incident and therefore those evidence tools could not provide corroboration.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Automated PHP/WordPress probe traffic reached target privatekind; reviewed HTTP events received 301 or 404 outcomes [http:[redacted], http:[redacted], http:4977296b-36bf-42d0-80ca-360cf377
- Observed impact is limited to scanning and request handling; the cited HTTP evidence does not prove successful exploitation or workload compromise [http:[redacted], http:[redacted]].
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
The incident is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not a confirmed compromise. The detector aggregated 39 requests across 20 probe paths in roughly 4.3 seconds, and the reviewed immutable HTTP records consistently classify the requests as php_or_wordpress_probe traffic from the same source cluster to target privatekind [http:[redacted], http:[redacted], http:[redacted]]. Sampled responses were redirects or rejections (301/404), with no request bodies [same references]. This supports a reconnaissance/enumeration verdict. It does not establish exploitation, command execution, persistence, or outbound activity; no process or flow evidence was cited by the incident and therefore those evidence tools could not provide corroboration.