Back to evidence

Sanitized live incident

Opportunistic scan

Native source identity and targetable endpoints are private.

mediumopen
Confidence
96%
First seen
Sep 1, 7:08:58 PM PDT
Evidence through
Sep 1, 7:10:05 PM PDT
AI status
Complete
True positive99% confidence

This is a true positive for opportunistic reconnaissance/web-shell path enumeration against target privatekind, not a confirmed compromise. Verified HTTP summaries show rapid, bodyless GET requests categorized as PHP or WordPress probes from the same source traffic cluster. The sampled responses were redirects or not-found responses with no server-generated command output. The incident cites no process- or flow-plane event IDs, so the available evidence does not establish command execution, outbound communication, persistence, or other post-exploitation impact.

Attack stage
Reconnaissance / PHP and WordPress web-shell path discovery
Model
gpt-5.6-sol · 7 evidence calls

Observed impact

  • Inbound web-shell enumeration traffic reached the HTTP gateway.
  • No successful exploitation or downstream host/network consequence is demonstrated by the cited evidence.

Deterministic signals

Http.php webshell enumeration96%

Rapid enumeration of PHP and WordPress web-shell paths

460 observations · 12 http

Explicit uncertainty

  • The incident cites no process-plane event IDs. Process evidence could not be retrieved, so the available evidence cannot determine whether any workload process activity occurred independently or as a consequence of these requests.
  • The incident cites no flow-plane event IDs. Flow evidence could not be retrieved, so the available evidence cannot assess contemporaneous outbound connections.
  • The source key identifies a traffic cluster, not necessarily one person or system; it may represent a proxy, NAT gateway, or multiple workers.
  • Target-to-workload affinity is inferred from configured routing rather than an observed per-request trace edge.
  • HTTP redirect or rejection status does not by itself prove exploit failure; the conclusion is limited to the absence of execution evidence in the bounded cited summaries.

Recommended actions

  1. Retain the HTTP evidence and monitor the source cluster for continued probing, method changes, non-empty payloads, authentication attempts, or successful content retrieval.
  2. Review the probed target for unintended PHP files, WordPress components, uploaded scripts, and exposed administrative paths; remove or restrict anything not required.
  3. Confirm gateway redirect/rejection behavior and ensure access controls, patching, and upload restrictions are current.
  4. If the source cluster continues at high volume, consider proportionate rate limiting or blocking according to organizational policy.
  5. Correlate with workload process and network telemetry if separately available before asserting compromise or closing the incident as impact-free.