Back to cases

Live public case

Opportunistic scan

Last activity Sep 1, 7:10:05 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

This is a true positive for opportunistic reconnaissance/web-shell path enumeration against target privatekind, not a confirmed compromise. Verified HTTP summaries show rapid, bodyless GET requests categorized as PHP or WordPress probes from the same source traffic cluster. The sampled responses were redirects or not-found responses with no server-generated command output. The incident cites no process- or flow-plane event IDs, so the available evidence does not establish command execution, outbound communication, persistence, or other post-exploitation impact.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Inbound web-shell enumeration traffic reached the HTTP gateway.
  • No successful exploitation or downstream host/network consequence is demonstrated by the cited evidence.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      This is a true positive for opportunistic reconnaissance/web-shell path enumeration against target privatekind, not a confirmed compromise. Verified HTTP summaries show rapid, bodyless GET requests categorized as PHP or WordPress probes from the same source traffic cluster. The sampled responses were redirects or not-found responses with no server-generated command output. The incident cites no process- or flow-plane event IDs, so the available evidence does not establish command execution, outbound communication, persistence, or other post-exploitation impact.