Back to evidence

Sanitized live incident

Opportunistic scan

Native source identity and targetable endpoints are private.

mediumopen
Confidence
96%
First seen
Aug 23, 6:13:03 AM PDT
Evidence through
Aug 23, 6:13:31 AM PDT
AI status
Complete
True positive99% confidence

This is a true positive for automated reconnaissance/web-shell path enumeration, not a confirmed compromise. The detector aggregated 232 requests across 118 PHP/WordPress probe paths in about 28 seconds, while the cited HTTP outcomes were redirects or rejections (for example, HTTP [redacted], [redacted], [redacted], and [redacted]). HTTP status does not independently prove exploit failure, and the incident provides no cited process or flow identities with which to determine workload execution or outbound network consequences.

Attack stage
Reconnaissance / web-shell path discovery
Model
gpt-5.6-sol · 6 evidence calls

Observed impact

  • Observed impact is rapid inbound enumeration against target privatekind; representative requests received 301 or 404 outcomes [redacted].
  • No workload execution, persistence, lateral movement, outbound callback, or data theft is established by the available incident evidence; process and flow consequence assessment remains unavailable.

Deterministic signals

Http.php webshell enumeration96%

Rapid enumeration of PHP and WordPress web-shell paths

232 observations · 12 http

Explicit uncertainty

  • No process-plane event identities are cited by this incident. The process evidence query therefore could not determine whether any workload execution occurred, and HTTP events cannot be used as process identities.
  • No flow-plane event identities are cited by this incident. The flow evidence query therefore could not determine whether any correlated outbound connection occurred, and HTTP events cannot be used as flow identities.
  • The source_key is a derived traffic/workload cluster and may represent a proxy, NAT gateway, or multiple workers rather than one actor.
  • Configured target routing does not provide an observed per-request trace edge to a specific downstream workload.
  • Although the cited outcomes are redirects/rejections, HTTP status alone cannot exclude an uncited server-side consequence.

Recommended actions

  1. Keep or tune gateway rejection and rate-limiting controls for this probe pattern; if policy permits, temporarily block the source cluster while recognizing that it is not a verified individual identity.
  2. Review application and gateway logs around 2026-08-23T13[redacted]03Z–[redacted]31Z for accepted follow-up requests, authentication events, or anomalous responses not represented in this incident.
  3. Verify that PHP/WordPress administration, upload, and known web-shell paths are not exposed; remove unused components and patch deployed applications and plugins.
  4. If process and network telemetry exists outside this bounded incident, correlate it to the target and time window before concluding that no execution or outbound activity occurred. Escalate containment only if corroborating consequence evidence appears.