Sanitized live incident
Opportunistic scan
Native source identity and targetable endpoints are private.
- Confidence
- 96%
- First seen
- Aug 30, 1:47:21 AM PDT
- Evidence through
- Aug 30, 1:47:34 AM PDT
- AI status
- Complete
The incident is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not for successful exploitation. The detector aggregated 39 requests across 20 probe paths in roughly 4.3 seconds. Verified HTTP summaries identify sampled requests as GETs in the php_or_wordpress_probe category; the first returned a 301 with an empty response body and the next returned a 404. The incident's cited HTTP evidence records only redirects or rejections, with no observed exploit consequence. No process or flow evidence references were available in this incident, so execution, outbound activity, and compromise cannot be determined from those planes.
- Attack stage
- Reconnaissance / opportunistic web-shell path enumeration
- Model
- gpt-5.6-sol · 5 evidence calls
Observed impact
- Observed impact is limited to rapid inbound reconnaissance and web-shell path probing; successful exploitation or workload compromise is not established.
Deterministic signals
Rapid enumeration of PHP and WordPress web-shell paths
116 observations · 12 httpExplicit uncertainty
- No process or flow event references are cited by this incident; attempts to query those evidence planes with the available HTTP IDs were rejected. Consequently, workload process execution and contemporaneous outbound connectivity cannot be assessed from bounded evidence.
- The source key is a traffic cluster and may represent a proxy, NAT gateway, or multiple workers rather than a unique actor.
- Target routing indicates downstream workload affinity but does not provide an observed per-request trace edge.
- HTTP rejection or redirect status does not by itself prove absence of server-side effects; the available HTTP summaries contain no server-generated command output, and no process evidence is available to test for execution.
Recommended actions
- Continue monitoring this source cluster for retries, path changes, authentication attempts, or requests that receive non-rejection responses.
- Apply proportionate gateway rate limiting or temporary blocking to the source cluster if consistent with policy, accounting for the possibility of shared proxy or NAT infrastructure.
- Review the target's deployed PHP and WordPress files against expected inventory and remove or quarantine any unauthorized web-shell-like artifacts.
- Preserve relevant gateway and workload logs around 2026-08-30T08[redacted]21Z–[redacted]26Z; investigate further if later process, file, or outbound-flow telemetry becomes available.
- No emergency workload isolation is justified by the current evidence alone; escalate containment only if additional evidence shows execution, file modification, or suspicious egress.