Sanitized live incident
Opportunistic scan
Native source identity and targetable endpoints are private.
mediumopen
- Confidence
- 96%
- First seen
- Aug 31, 7:46:23 PM PDT
- Evidence through
- Aug 31, 7:46:43 PM PDT
- AI status
- Complete
True positive98% confidence
This is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not for successful exploitation. The deterministic detector recorded 41 requests against 20 probe paths in roughly 4.7 seconds. The retained HTTP summaries consistently classify the requests as PHP/WordPress probes from one traffic cluster to target privatekind and show only 301 redirects or 404 responses. No cited process or flow evidence is available to establish command execution, persistence, outbound activity, or other compromise consequences.
- Attack stage
- Reconnaissance / discovery: PHP and WordPress web-shell endpoint enumeration
- Model
- gpt-5.6-sol · 16 evidence calls
Observed impact
- The observed activity attempted to discover exposed PHP or WordPress web-shell endpoints.
- No successful exploitation or adverse workload consequence is demonstrated by the available evidence.
Deterministic signals
Rapid enumeration of PHP and WordPress web-shell paths
182 observations · 12 httpExplicit uncertainty
- The source key denotes a traffic or workload cluster, not a guaranteed individual identity; it may represent a proxy, NAT gateway, or multiple workers.
- No process evidence identity is cited by this incident, so the available evidence cannot determine whether any temporally related workload process executed.
- No flow evidence identity is cited by this incident, so the available evidence cannot determine whether any related outbound connection occurred.
- Configured target routing does not establish an observed per-request trace edge to a particular downstream workload.
- The bounded HTTP summaries exclude raw response content, so the 404 response bodies cannot be semantically inspected here; HTTP status alone is not proof of exploit failure.
Recommended actions
- Continue monitoring the source cluster for follow-on requests that receive materially different responses or correlate with verified process or flow evidence.
- Apply policy-appropriate rate limiting or temporary blocking for repeated web-shell enumeration if this traffic is unauthorized.
- Verify that PHP and WordPress components, plugins, themes, and upload directories on the routed application are current and do not contain unexpected executable files.
- Retain the relevant gateway and workload telemetry and escalate if subsequent evidence shows command output, process execution, file modification, or novel outbound connectivity.