Back to cases

Live public case

Opportunistic scan

Last activity Aug 24, 9:57:27 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

High-confidence true positive for opportunistic web-shell/path reconnaissance against target privatekind. The incident aggregates 39 requests across 20 PHP/WordPress probe paths in under five seconds, and verified HTTP summaries confirm rapid GET probes from one source cluster with redirect/rejection outcomes (HTTP evidence [redacted] through [redacted]). This establishes the scan, but not compromise: no process or flow evidence is cited by the incident, and HTTP status by itself cannot prove exploit failure.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Observed impact is limited to a brief burst of inbound reconnaissance requests; the cited HTTP evidence does not establish command execution, persistence, data access, or outbound activity.
  • All 39 requests were characterized by the detector as redirect/rejection outcomes; there is no demonstrated successful web-shell interaction in the available bounded evidence.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      High-confidence true positive for opportunistic web-shell/path reconnaissance against target privatekind. The incident aggregates 39 requests across 20 PHP/WordPress probe paths in under five seconds, and verified HTTP summaries confirm rapid GET probes from one source cluster with redirect/rejection outcomes (HTTP evidence [redacted] through [redacted]). This establishes the scan, but not compromise: no process or flow evidence is cited by the incident, and HTTP status by itself cannot prove exploit failure.