Back to cases

Live public case

Opportunistic scan

Last activity Aug 26, 2:50:23 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is a true positive for opportunistic reconnaissance/web-shell path enumeration, not for successful compromise. The traffic cluster generated a rapid burst that the detector aggregated as 39 requests across 20 PHP/WordPress probe paths from [redacted].438Z through [redacted].271Z. Verified HTTP examples are GET requests categorized as php_or_wordpress_probe and received 301 redirects or 404 rejections; no bounded process or flow evidence is cited to establish execution or follow-on activity. [HTTP: [redacted], [redacted], [redacted], [redacted], [redacted]]

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • A brief burst of 39 inbound PHP/WordPress probe requests targeted the service; the incident reports 20 unique probe paths. [HTTP: [redacted] through [redacted]]
  • No successful exploitation or downstream workload consequence is established; the verified HTTP examples show only redirects or rejections. [HTTP: [redacted], [redacted], 701bbc73-cd95-43b
  • [redacted], [redacted]]

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Opportunistic scanopen

      The incident is a true positive for opportunistic reconnaissance/web-shell path enumeration, not for successful compromise. The traffic cluster generated a rapid burst that the detector aggregated as 39 requests across 20 PHP/WordPress probe paths from [redacted].438Z through [redacted].271Z. Verified HTTP examples are GET requests categorized as php_or_wordpress_probe and received 301 redirects or 404 rejections; no bounded process or flow evidence is cited to establish execution or follow-on activity. [HTTP: [redacted], [redacted], [redacted], [redacted], [redacted]]