Live public case
Opportunistic scan
Last activity Aug 26, 2:50:23 PM PDT
Evidence-grounded assessment
Not required
The incident is a true positive for opportunistic reconnaissance/web-shell path enumeration, not for successful compromise. The traffic cluster generated a rapid burst that the detector aggregated as 39 requests across 20 PHP/WordPress probe paths from [redacted].438Z through [redacted].271Z. Verified HTTP examples are GET requests categorized as php_or_wordpress_probe and received 301 redirects or 404 rejections; no bounded process or flow evidence is cited to establish execution or follow-on activity. [HTTP: [redacted], [redacted], [redacted], [redacted], [redacted]]
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- A brief burst of 39 inbound PHP/WordPress probe requests targeted the service; the incident reports 20 unique probe paths. [HTTP: [redacted] through [redacted]]
- No successful exploitation or downstream workload consequence is established; the verified HTTP examples show only redirects or rejections. [HTTP: [redacted], [redacted], 701bbc73-cd95-43b
- [redacted], [redacted]]
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Opportunistic scanopen
The incident is a true positive for opportunistic reconnaissance/web-shell path enumeration, not for successful compromise. The traffic cluster generated a rapid burst that the detector aggregated as 39 requests across 20 PHP/WordPress probe paths from [redacted].438Z through [redacted].271Z. Verified HTTP examples are GET requests categorized as php_or_wordpress_probe and received 301 redirects or 404 rejections; no bounded process or flow evidence is cited to establish execution or follow-on activity. [HTTP: [redacted], [redacted], [redacted], [redacted], [redacted]]