Live public case
Opportunistic scan
Last activity Aug 19, 8:31:28 PM PDT
Evidence-grounded assessment
Not required
High-confidence true positive for opportunistic PHP/WordPress web-shell path enumeration, not for successful exploitation. The incident’s immutable detector output reports 39 requests across 20 probe paths in about 4.4 seconds; the verified HTTP samples are GET requests categorized as PHP/WordPress probes and show only 301 redirects or 404 rejections. No process or flow evidence is cited by this incident, so execution, outbound activity, or compromise cannot be determined from those planes.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Confirmed hostile or unauthorized-looking enumeration activity against the HTTP target.
- Observed HTTP impact was limited to rapid probe traffic and redirect/rejection responses; no successful exploitation consequence is established.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
High-confidence true positive for opportunistic PHP/WordPress web-shell path enumeration, not for successful exploitation. The incident’s immutable detector output reports 39 requests across 20 probe paths in about 4.4 seconds; the verified HTTP samples are GET requests categorized as PHP/WordPress probes and show only 301 redirects or 404 rejections. No process or flow evidence is cited by this incident, so execution, outbound activity, or compromise cannot be determined from those planes.