Sanitized live incident
Opportunistic scan
Native source identity and targetable endpoints are private.
- Confidence
- 96%
- First seen
- Aug 27, 1:31:09 PM PDT
- Evidence through
- Aug 27, 1:31:31 PM PDT
- AI status
- Complete
This is a true positive for opportunistic reconnaissance/web-shell enumeration, not a confirmed compromise. The detector derived 39 requests across 20 PHP/WordPress probe paths in about 4.8 seconds, and verified HTTP examples are GETs categorized as php_or_wordpress_probe with distinct path hashes [redacted]. The incident records redirect/rejection-only outcomes for all 39 requests. That supports an attempted discovery scan but does not, by HTTP status alone, prove exploit failure. No process or flow evidence references were cited by this incident, so execution, outbound activity, persistence, or other compromise consequences cannot be assessed from the available evidence.
- Attack stage
- Reconnaissance / discovery of PHP and WordPress web-shell paths
- Model
- gpt-5.6-sol · 6 evidence calls
Observed impact
- Observed impact is limited to a rapid inbound path-enumeration burst against the target [redacted].
- No compromise consequence is demonstrated; redirect/rejection outcomes do not by themselves establish exploit success or failure [redacted].
Deterministic signals
Rapid enumeration of PHP and WordPress web-shell paths
178 observations · 12 httpExplicit uncertainty
- No process-plane evidence references are cited by this incident; the process-evidence query therefore could not assess execution or workload-side consequences.
- No flow-plane evidence references are cited by this incident; the flow-evidence query therefore could not assess correlated outbound connections.
- HTTP status and the derived redirect/rejection outcome do not alone establish exploit failure; no server-generated command output is identified in the available summaries.
- The source_key is a traffic cluster and may represent a proxy, NAT gateway, or multiple workers rather than one actor.
- Downstream workload affinity is inferred from configured target routing and is not an observed per-request trace edge.
Recommended actions
- Continue monitoring the source traffic cluster and target for follow-on requests, especially command-bearing requests, uploads, authentication attempts, or successful responses at the probed paths.
- Verify that the probed PHP/WordPress and web-shell-like paths do not exist on the target, and review application/origin logs around 2026-08-27T20[redacted]09Z–[redacted]14Z for matching requests or unexpected handlers.
- Review workload process and network telemetry for the same interval if available; escalate only if it shows suspicious execution, file creation, or outbound activity.
- Apply proportionate rate limiting or blocking to repeated enumeration traffic according to policy, while accounting for the possibility that the source cluster represents shared infrastructure.
- Maintain current PHP/WordPress components and remove unused plugins, themes, scripts, and administrative endpoints.