Sanitized live incident
Opportunistic scan
Native source identity and targetable endpoints are private.
mediumopen
- Confidence
- 96%
- First seen
- Aug 19, 8:30:57 PM PDT
- Evidence through
- Aug 19, 8:31:28 PM PDT
- AI status
- Complete
True positive98% confidence
High-confidence true positive for opportunistic PHP/WordPress web-shell path enumeration, not for successful exploitation. The incident’s immutable detector output reports 39 requests across 20 probe paths in about 4.4 seconds; the verified HTTP samples are GET requests categorized as PHP/WordPress probes and show only 301 redirects or 404 rejections. No process or flow evidence is cited by this incident, so execution, outbound activity, or compromise cannot be determined from those planes.
- Attack stage
- Reconnaissance / web-shell discovery and enumeration
- Model
- gpt-5.6-sol · 5 evidence calls
Observed impact
- Confirmed hostile or unauthorized-looking enumeration activity against the HTTP target.
- Observed HTTP impact was limited to rapid probe traffic and redirect/rejection responses; no successful exploitation consequence is established.
Deterministic signals
Rapid enumeration of PHP and WordPress web-shell paths
293 observations · 12 httpExplicit uncertainty
- The source key is a traffic/workload cluster and may represent a proxy, NAT gateway, multiple workers, or another shared origin rather than one actor.
- Downstream workload affinity is inferred from configured target routing and is not an observed per-request trace edge.
- No process evidence is cited by this incident, so the available evidence cannot determine whether any workload process execution occurred.
- No flow evidence is cited by this incident, so the available evidence cannot determine whether temporally related outbound network activity occurred.
- The bounded HTTP summaries exclude raw body content; therefore response status and body hashes alone cannot conclusively exclude server-generated exploit output in every response.
Recommended actions
- Keep the incident categorized as attempted reconnaissance/enumeration unless later process, application, or flow telemetry establishes exploitation consequences.
- Review the target’s access/application logs and file inventory for the probed PHP or WordPress paths, especially if the target is not expected to expose PHP or WordPress.
- Apply or confirm rate limiting and gateway/WAF rules for rapid web-shell path enumeration; block the source cluster only if consistent with operational policy and collateral-risk review.
- Monitor for follow-on requests from the same cluster and correlate any new process or outbound-flow evidence before escalating to compromise containment.
- Verify that unnecessary PHP/WordPress components and known web-shell files are absent or inaccessible, and keep internet-facing software patched.