Live public case
Opportunistic scan
Last activity Aug 24, 10:31:19 PM PDT
Evidence-grounded assessment
Not required
The incident is a true positive for opportunistic reconnaissance/web-shell path enumeration, not for confirmed compromise. The cited HTTP series records a rapid burst against PHP/WordPress probe-path categories, and the detector-derived aggregate reports 41 requests across 20 unique probe paths. Available outcomes are redirects or rejections, including 301 and 404 responses. HTTP status alone cannot prove exploit failure, but the available evidence contains no demonstrated execution or other downstream consequence. Process and flow evidence could not be retrieved because this incident cites no events from those planes.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- A brief burst of 41 HTTP probes reached the target and produced only redirect/rejection outcomes in the cited evidence.
- No command execution, outbound connection, persistence, lateral movement, or data access is established by the available evidence.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
The incident is a true positive for opportunistic reconnaissance/web-shell path enumeration, not for confirmed compromise. The cited HTTP series records a rapid burst against PHP/WordPress probe-path categories, and the detector-derived aggregate reports 41 requests across 20 unique probe paths. Available outcomes are redirects or rejections, including 301 and 404 responses. HTTP status alone cannot prove exploit failure, but the available evidence contains no demonstrated execution or other downstream consequence. Process and flow evidence could not be retrieved because this incident cites no events from those planes.