Live public case
Opportunistic scan
Last activity Aug 27, 7:56:13 PM PDT
Evidence-grounded assessment
Not required
True positive for opportunistic PHP/WordPress web-shell path enumeration, not for confirmed compromise. The incident records 236 requests spanning 119 probe paths in about 29 seconds. The inspected complete HTTP summaries show bodyless GET requests categorized as PHP/WordPress probes and responses of 301 or 404. No process or flow evidence is cited by the incident, so command execution and downstream network consequences are not established.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Observed impact is limited to rapid application-path probing; the supplied evidence does not establish command execution, persistence, data access, exfiltration, or an attacker-induced outbound connection.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
True positive for opportunistic PHP/WordPress web-shell path enumeration, not for confirmed compromise. The incident records 236 requests spanning 119 probe paths in about 29 seconds. The inspected complete HTTP summaries show bodyless GET requests categorized as PHP/WordPress probes and responses of 301 or 404. No process or flow evidence is cited by the incident, so command execution and downstream network consequences are not established.