Back to cases

Live public case

Opportunistic scan

Last activity Aug 29, 8:17:36 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is a true positive for opportunistic reconnaissance: one derived source cluster rapidly issued 39 GET requests covering 20 distinct PHP/WordPress probe paths against target privatekind between [redacted].030Z and [redacted].351Z. Representative complete captures returned redirects or rejections, including 301 and 404 responses (HTTP evidence [redacted], [redacted], and [redacted]). This establishes scanning/enumeration, but the available evidence does not establish web-shell access, command execution, persistence, or outbound activity.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Reconnaissance traffic reached the target HTTP service; the cited HTTP evidence shows redirect/rejection outcomes rather than a verified exploit consequence.
  • No verified workload execution, persistence, lateral movement, outbound connection, or data loss is established by the evidence available for this incident.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The incident is a true positive for opportunistic reconnaissance: one derived source cluster rapidly issued 39 GET requests covering 20 distinct PHP/WordPress probe paths against target privatekind between [redacted].030Z and [redacted].351Z. Representative complete captures returned redirects or rejections, including 301 and 404 responses (HTTP evidence [redacted], [redacted], and [redacted]). This establishes scanning/enumeration, but the available evidence does not establish web-shell access, command execution, persistence, or outbound activity.