Back to cases

Live public case

Opportunistic scan

Last activity Aug 24, 12:09:21 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is a true positive for opportunistic reconnaissance: a single derived traffic cluster rapidly issued GET requests categorized as PHP or WordPress probes, and the detector derived 39 requests across 20 unique probe paths in roughly 4.5 seconds. The available HTTP evidence shows only redirects or rejection responses and does not establish successful web-shell access or code execution. This verdict confirms the scan/enumeration activity, not host compromise. No process- or flow-plane evidence is cited by the incident, so downstream execution and network consequences remain unverified.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Brief unsolicited enumeration traffic reached target privatekind.
  • No successful exploitation or workload consequence is established by the available evidence.
  • All detector-recorded HTTP outcomes were redirects or rejections.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The incident is a true positive for opportunistic reconnaissance: a single derived traffic cluster rapidly issued GET requests categorized as PHP or WordPress probes, and the detector derived 39 requests across 20 unique probe paths in roughly 4.5 seconds. The available HTTP evidence shows only redirects or rejection responses and does not establish successful web-shell access or code execution. This verdict confirms the scan/enumeration activity, not host compromise. No process- or flow-plane evidence is cited by the incident, so downstream execution and network consequences remain unverified.