Sanitized live incident
Opportunistic scan
Native source identity and targetable endpoints are private.
- Confidence
- 96%
- First seen
- Aug 26, 1:54:33 PM PDT
- Evidence through
- Aug 26, 1:54:40 PM PDT
- AI status
- Complete
High-confidence true positive for rapid opportunistic PHP/WordPress web-shell path enumeration against target privatekind. Verified HTTP summaries show repeated GET requests categorized as php_or_wordpress_probe, with distinct path hashes, from one derived source cluster over roughly 4.4 seconds. The incident detector reports 38 requests across 20 unique probe paths. Observed HTTP outcomes were redirects or rejections, but status codes alone do not prove exploit failure. No process or flow evidence is cited by this incident, so successful execution or follow-on network activity is neither demonstrated nor conclusively excluded.
- Attack stage
- Reconnaissance / web-shell path discovery
- Model
- gpt-5.6-sol · 8 evidence calls
Observed impact
- Confirmed PHP/WordPress web-shell path enumeration reached the HTTP service.
- No demonstrated command execution, persistence, outbound connection, lateral movement, or data loss in the available cited evidence.
Deterministic signals
Rapid enumeration of PHP and WordPress web-shell paths
64 observations · 12 httpExplicit uncertainty
- No process or flow evidence references are cited by this incident; the corresponding evidence tools could not return lifecycle or conntrack summaries. Execution and follow-on network consequences therefore cannot be independently assessed.
- HTTP 301/404 status codes do not conclusively establish exploit failure, and raw response bodies are unavailable.
- The source_key is a traffic cluster, not a proven identity; it may represent a proxy, NAT gateway, or multiple workers.
- Downstream workload affinity is inferred from configured target routing rather than an observed per-request trace edge.
Recommended actions
- Correlate the cited HTTP events with application, reverse-proxy, workload process, and network telemetry for the same time window if available.
- Review the target for unexpected PHP files or web shells and verify that unused PHP/WordPress endpoints are absent or inaccessible.
- Apply proportionate rate limiting or blocking to repeated probe patterns; do not treat the source cluster as a uniquely identified actor.
- Monitor for recurrence, uploads, command-like parameters, unexpected child processes, or novel outbound connections.