Live public case
Confirmed compromise
Last activity Aug 28, 9:15:03 PM PDT
Evidence-grounded assessment
Not required
True positive: HTTP evidence proves successful command injection and root-level command execution in the responding workload, even though the responses were HTTP 400. The strongest event contains shell-command input and non-reflected process-identity output identifying UID 0 ([redacted]); another response disclosed non-reflected kernel information ([redacted]). Event-driven process telemetry independently shows root shells and discovery commands in the correlated workload, followed by sensitive-target and shared-resource activity. The detector's confirmed state and confirmed-compromise classification are therefore supported. Process timing does not establish a unique request-to-process edge, and no cited flow evidence was available to assess outbound consequences.
- Protected workloads
- Protected workload A · Protected workload B
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Confirmed root execution
- Correlated process exited
- Remote command execution
- Root execution
- Sensitive file access command observed
- Server identity disclosure
- Shared resource access observed
- Shared resource mutation observed
- Shell spawned
- State changing http activity after compromise
- System discovery
- System information disclosure
- Workload discovery process spawned
- Workload root shell
- Remote command execution as root was proven in the responding workload.
- Root shell and system-discovery processes were observed in the correlated workload.
- A root shell targeted a sensitive file and mutated a shared resource; child processes accessed the shared resource and sensitive target.
- Non-reflected process identity and kernel information were disclosed in HTTP responses.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Confirmed compromiseconfirmed
True positive: HTTP evidence proves successful command injection and root-level command execution in the responding workload, even though the responses were HTTP 400. The strongest event contains shell-command input and non-reflected process-identity output identifying UID 0 ([redacted]); another response disclosed non-reflected kernel information ([redacted]). Event-driven process telemetry independently shows root shells and discovery commands in the correlated workload, followed by sensitive-target and shared-resource activity. The detector's confirmed state and confirmed-compromise classification are therefore supported. Process timing does not establish a unique request-to-process edge, and no cited flow evidence was available to assess outbound consequences.