Back to evidence

Sanitized live incident

Opportunistic scan

Native source identity and targetable endpoints are private.

mediumopen
Confidence
96%
First seen
Aug 23, 5:33:07 AM PDT
Evidence through
Aug 23, 5:33:30 AM PDT
AI status
Complete
True positive98% confidence

The incident is a true positive for opportunistic reconnaissance/web-shell path enumeration, not for successful compromise. The detector recorded 218 requests spanning 110 probe paths in about 23 seconds from one derived source cluster. Verified representative requests were GETs categorized as PHP/WordPress probes and received 301 or 404 outcomes. No cited process or flow evidence was available to establish command execution, outbound activity, persistence, or any other post-request consequence, so impact remains unproven.

Attack stage
Reconnaissance — PHP/WordPress web-shell path enumeration
Model
gpt-5.6-sol · 8 evidence calls

Observed impact

  • Observed activity was limited to rapid HTTP-layer probing and enumeration.
  • No successful exploitation or post-request workload consequence was demonstrated by the available cited evidence.

Deterministic signals

Http.php webshell enumeration96%

Rapid enumeration of PHP and WordPress web-shell paths

218 observations · 12 http

Explicit uncertainty

  • The source key is a traffic/workload cluster, not a verified person or single agent; it may represent a proxy, NAT gateway, or multiple workers.
  • No process-plane event references were cited by this incident, so execution or other workload process consequences could not be assessed.
  • No flow-plane event references were cited by this incident, so correlated outbound network activity could not be assessed.
  • Configured target routing does not provide an observed per-request trace edge to a specific downstream workload.
  • HTTP status codes and bounded response summaries cannot conclusively exclude successful behavior outside the retained evidence window.

Recommended actions

  1. Continue monitoring the source cluster and apply temporary rate limiting or blocking if policy permits; do not treat the cluster key as a verified human identity.
  2. Review application and gateway logs around 2026-08-23T12[redacted]07Z–[redacted]31Z for follow-on requests, especially any non-rejected responses or requests carrying parameters or bodies.
  3. Verify that no unauthorized PHP files or WordPress artifacts exist under web-accessible paths, using normal integrity and deployment controls.
  4. Keep the web stack and any WordPress components patched, disable unused PHP endpoints, and retain least-privilege filesystem permissions.
  5. Escalate to workload containment only if subsequent process, file-integrity, or network evidence demonstrates execution or persistence.