Live public case
Opportunistic scan
Last activity Aug 20, 5:55:33 AM PDT
Evidence-grounded assessment
Not required
The cited HTTP evidence confirms a rapid, automated-looking PHP/WordPress path-enumeration scan against target privatekind. Representative requests were bodyless GETs categorized as php_or_wordpress_probe and produced only 301 redirects or 404 responses. This establishes reconnaissance/probing, not successful exploitation. No process or flow evidence references are present in the incident, so command execution, outbound activity, persistence, or other compromise consequences are not established.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Unauthorized reconnaissance reached the HTTP service and enumerated suspected PHP/WordPress web-shell locations.
- No successful exploitation or downstream workload impact is demonstrated by the cited evidence.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
The cited HTTP evidence confirms a rapid, automated-looking PHP/WordPress path-enumeration scan against target privatekind. Representative requests were bodyless GETs categorized as php_or_wordpress_probe and produced only 301 redirects or 404 responses. This establishes reconnaissance/probing, not successful exploitation. No process or flow evidence references are present in the incident, so command execution, outbound activity, persistence, or other compromise consequences are not established.