Back to evidence

Sanitized live incident

Opportunistic scan

Native source identity and targetable endpoints are private.

mediumopen
Confidence
96%
First seen
Aug 21, 9:31:19 PM PDT
Evidence through
Aug 21, 9:31:21 PM PDT
AI status
Complete
True positive98% confidence

This is a true positive for opportunistic reconnaissance: the cited traffic cluster rapidly enumerated PHP/WordPress probe paths on target privatekind. The aggregate signal records 38 requests across 20 unique probe paths, with all 38 receiving redirect or rejection outcomes, supported by HTTP evidence [redacted] through [redacted]. Representative capture-complete summaries show GET probes returning either an empty 301 or a 404 ([redacted]; [redacted]). This verifies the scan attempt, but does not establish successful exploitation or workload compromise. No process or flow references were cited by the incident, so consequence telemetry could not be evaluated.

Attack stage
Reconnaissance — PHP/WordPress web-shell path enumeration
Model
gpt-5.6-sol · 6 evidence calls

Observed impact

  • Confirmed impact is limited to rapid inbound probe traffic against target privatekind; the cited HTTP evidence establishes scanning but not successful execution or compromise ([redacted]; e15ff174-7aa1-4d13-a44d-72
  • No persistence, lateral movement, command-and-control, data theft, or host escape is established by the available incident evidence.

Deterministic signals

Http.php webshell enumeration96%

Rapid enumeration of PHP and WordPress web-shell paths

132 observations · 12 http

Explicit uncertainty

  • The source_key is a derived traffic/workload cluster and may represent a proxy, NAT gateway, multiple workers, or another shared source rather than one actor.
  • Downstream workload affinity is inferred from configured target routing; no observed per-request trace edge attributes every probe to a particular workload instance.
  • The incident cites no process-plane or flow-plane event IDs. Queries using the HTTP IDs were rejected as not process/flow evidence, so command execution, outbound connections, and other post-request consequences cannot be confirmed or excluded from those planes.
  • Exact paths, query strings, headers, and raw response bodies are intentionally unavailable in the bounded summaries; therefore the investigation cannot independently inspect response content beyond the exposed metadata.

Recommended actions

  1. Keep the incident open for short-term monitoring and alert on follow-up requests from the same traffic cluster, while recognizing that the cluster is not a guaranteed actor identity.
  2. Verify that the redirect/rejection controls remain enforced at both gateway and origin, and rate-limit or block repeated probe patterns according to policy.
  3. Review origin and workload telemetry around the incident window for unexpected PHP interpreter or shell process activity and unusual outbound connections, because no process or flow evidence was cited here.
  4. Confirm that no unauthorized PHP files or WordPress components exist in served document roots; patch or remove exposed PHP/WordPress software that is not required.
  5. Retain and correlate subsequent requests targeting the same probe categories to distinguish one-off opportunistic scanning from sustained exploitation attempts.