Back to evidence

Sanitized live incident

Opportunistic scan

Native source identity and targetable endpoints are private.

mediumopen
Confidence
96%
First seen
Aug 28, 6:16:38 AM PDT
Evidence through
Aug 28, 6:18:43 AM PDT
AI status
Complete
True positive98% confidence

The incident is a true positive for opportunistic reconnaissance: the traffic cluster rapidly issued GET requests categorized as PHP or WordPress probes against target privatekind, and the detector aggregated 38 requests spanning 20 unique probe paths. The cited HTTP outcomes were redirects or rejections, so this establishes web-shell path enumeration but not successful exploitation. No process or flow evidence is cited by the incident, leaving execution and downstream network consequences unproven.

Attack stage
Reconnaissance / PHP and WordPress web-shell path enumeration
Model
gpt-5.6-sol · 5 evidence calls

Observed impact

  • Automated enumeration of potential PHP and WordPress web-shell locations against the target.
  • No demonstrated command execution, persistence, outbound connection, or other compromise consequence in the available cited evidence.

Deterministic signals

Http.php webshell enumeration96%

Rapid enumeration of PHP and WordPress web-shell paths

522 observations · 12 http

Explicit uncertainty

  • The source_key is a derived traffic cluster and may represent a proxy, NAT gateway, or multiple workers; it is not a confirmed human or agent identity.
  • No process-plane or flow-plane event references are cited by this incident. Queries using the incident's HTTP IDs could not retrieve process or flow evidence, so command execution and outbound network consequences cannot be independently assessed rather than being proven absent.
  • Downstream workload affinity is inferred from configured target routing and is not an observed per-request trace edge.
  • HTTP rejection or redirect statuses do not by themselves prove exploit failure; the available summaries contain no command-output evidence, but evidence outside the retained incident scope could change the consequence assessment.

Recommended actions

  1. Continue monitoring this source cluster and related traffic for follow-on exploitation, upload attempts, authentication attacks, or successful responses.
  2. Apply proportionate rate limiting or blocking for repeated PHP/WordPress probe patterns at the gateway if consistent with operational policy.
  3. Verify that exposed PHP and WordPress components, plugins, and themes are current, and remove any unnecessary administrative or legacy endpoints.
  4. Review workload and application logs around the incident window for matching requests or anomalous file changes if higher assurance about non-compromise is required.