Sanitized live incident
Opportunistic scan
Native source identity and targetable endpoints are private.
mediumopen
- Confidence
- 96%
- First seen
- Aug 26, 10:36:53 PM PDT
- Evidence through
- Aug 26, 10:37:25 PM PDT
- AI status
- Complete
True positive99% confidence
This is a true positive for opportunistic reconnaissance: a rapid burst enumerated PHP and WordPress web-shell-style paths. The available HTTP evidence shows redirects and rejections, so the observed incident is scanning rather than a demonstrated compromise. No cited process or flow evidence was available to establish execution or outbound network consequences.
- Attack stage
- Reconnaissance / web-shell path discovery
- Model
- gpt-5.6-sol · 5 evidence calls
Observed impact
- Confirmed hostile or unauthorized-looking web-path enumeration against the target.
- No workload execution, persistence, outbound connection, or data-loss consequence is established by the available evidence.
Deterministic signals
Rapid enumeration of PHP and WordPress web-shell paths
286 observations · 12 httpExplicit uncertainty
- No process-plane event is cited by this incident, so the available evidence cannot independently determine whether any workload process executed near the requests.
- No flow-plane event is cited by this incident, so the available evidence cannot independently assess contemporaneous outbound connections.
- HTTP status codes alone cannot prove exploit failure; the available summaries do not expose affirmative server-generated command output or another execution indicator.
- The source key is a traffic cluster and may represent a proxy, NAT gateway, or multiple workers rather than one actor.
- Target routing affinity is configured inference rather than an observed per-request workload trace edge.
Recommended actions
- Retain and monitor the source cluster for recurrence; apply rate limiting or temporary blocking if consistent with policy and business risk.
- Verify that the probed PHP or WordPress paths are not deployed and remove any unexpected scripts or web shells found through normal asset-integrity procedures.
- Review application, reverse-proxy, and workload telemetry around 2026-08-27T05[redacted]53Z–[redacted]58Z for request handling, file changes, authentication anomalies, or execution indicators.
- Continue process and egress monitoring for the target; escalate only if later evidence shows execution, persistence, suspicious outbound activity, or data access.