Back to evidence

Sanitized live incident

Opportunistic scan

Native source identity and targetable endpoints are private.

mediumopen
Confidence
96%
First seen
Aug 26, 1:54:09 AM PDT
Evidence through
Aug 26, 1:55:04 AM PDT
AI status
Complete
True positive98% confidence

The alert accurately identifies a rapid, opportunistic PHP/WordPress web-shell path-enumeration campaign against target privatekind. The cited HTTP evidence supports real probing activity, while the incident aggregate records 38 requests across 20 probe paths. Observed HTTP outcomes were redirects or rejections, but status codes alone cannot prove that every probe failed. No process or flow evidence was cited by this incident, so there is no verified command execution, persistence, outbound connection, or other compromise consequence.

Attack stage
Reconnaissance/discovery: PHP and WordPress web-shell path enumeration
Model
gpt-5.6-sol · 6 evidence calls

Observed impact

  • Confirmed unwanted web-shell path enumeration against the web service; no verified post-exploitation impact in the available cited evidence.

Deterministic signals

Http.php webshell enumeration96%

Rapid enumeration of PHP and WordPress web-shell paths

461 observations · 12 http

Explicit uncertainty

  • The source key is a traffic/workload cluster and may represent a proxy, NAT gateway, multiple workers, or another shared origin; it is not a proven human or agent identity.
  • Downstream workload affinity is inferred from configured target routing rather than an observed per-request trace edge.
  • The incident cites no process-plane or flow-plane event identities retrievable by the respective evidence tools, so execution and outbound-network consequences cannot be independently assessed.
  • HTTP redirect/rejection status alone cannot conclusively prove that no vulnerable resource was reached; exact raw response bodies are outside the bounded evidence available here.

Recommended actions

  1. Continue monitoring the source cluster and target for follow-on exploit attempts, authentication abuse, uploads, or anomalous requests.
  2. Apply or verify rate limiting and protected workload filtering for repeated PHP/WordPress web-shell path enumeration, using care because the source key may represent shared infrastructure.
  3. Confirm that the probed PHP/WordPress paths and known web-shell filenames are absent or inaccessible on the deployed application, and review deployment integrity through normal operational controls.
  4. Preserve the cited gateway telemetry and correlate it with workload logs around 2026-08-26T08[redacted]09Z–[redacted]15Z if deeper assurance about backend handling is required.