Sanitized live incident
Opportunistic scan
Native source identity and targetable endpoints are private.
mediumopen
- Confidence
- 96%
- First seen
- Aug 28, 6:16:38 AM PDT
- Evidence through
- Aug 28, 6:18:43 AM PDT
- AI status
- Complete
True positive98% confidence
The incident is a true positive for opportunistic reconnaissance: the traffic cluster rapidly issued GET requests categorized as PHP or WordPress probes against target privatekind, and the detector aggregated 38 requests spanning 20 unique probe paths. The cited HTTP outcomes were redirects or rejections, so this establishes web-shell path enumeration but not successful exploitation. No process or flow evidence is cited by the incident, leaving execution and downstream network consequences unproven.
- Attack stage
- Reconnaissance / PHP and WordPress web-shell path enumeration
- Model
- gpt-5.6-sol · 5 evidence calls
Observed impact
- Automated enumeration of potential PHP and WordPress web-shell locations against the target.
- No demonstrated command execution, persistence, outbound connection, or other compromise consequence in the available cited evidence.
Deterministic signals
Rapid enumeration of PHP and WordPress web-shell paths
522 observations · 12 httpExplicit uncertainty
- The source_key is a derived traffic cluster and may represent a proxy, NAT gateway, or multiple workers; it is not a confirmed human or agent identity.
- No process-plane or flow-plane event references are cited by this incident. Queries using the incident's HTTP IDs could not retrieve process or flow evidence, so command execution and outbound network consequences cannot be independently assessed rather than being proven absent.
- Downstream workload affinity is inferred from configured target routing and is not an observed per-request trace edge.
- HTTP rejection or redirect statuses do not by themselves prove exploit failure; the available summaries contain no command-output evidence, but evidence outside the retained incident scope could change the consequence assessment.
Recommended actions
- Continue monitoring this source cluster and related traffic for follow-on exploitation, upload attempts, authentication attacks, or successful responses.
- Apply proportionate rate limiting or blocking for repeated PHP/WordPress probe patterns at the gateway if consistent with operational policy.
- Verify that exposed PHP and WordPress components, plugins, and themes are current, and remove any unnecessary administrative or legacy endpoints.
- Review workload and application logs around the incident window for matching requests or anomalous file changes if higher assurance about non-compromise is required.