Back to cases

Live public case

Confirmed compromise

Last activity Aug 28, 9:15:03 PM PDT

criticalImpact confirmed

Evidence-grounded assessment

Not required

True positive: HTTP evidence proves successful command injection and root-level command execution in the responding workload, even though the responses were HTTP 400. The strongest event contains shell-command input and non-reflected process-identity output identifying UID 0 ([redacted]); another response disclosed non-reflected kernel information ([redacted]). Event-driven process telemetry independently shows root shells and discovery commands in the correlated workload, followed by sensitive-target and shared-resource activity. The detector's confirmed state and confirmed-compromise classification are therefore supported. Process timing does not establish a unique request-to-process edge, and no cited flow evidence was available to assess outbound consequences.

Protected workloads
Protected workload A · Protected workload B
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Confirmed root execution
  • Correlated process exited
  • Remote command execution
  • Root execution
  • Sensitive file access command observed
  • Server identity disclosure
  • Shared resource access observed
  • Shared resource mutation observed
  • Shell spawned
  • State changing http activity after compromise
  • System discovery
  • System information disclosure
  • Workload discovery process spawned
  • Workload root shell
  • Remote command execution as root was proven in the responding workload.
  • Root shell and system-discovery processes were observed in the correlated workload.
  • A root shell targeted a sensitive file and mutated a shared resource; child processes accessed the shared resource and sensitive target.
  • Non-reflected process identity and kernel information were disclosed in HTTP responses.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Confirmed compromiseconfirmed

      True positive: HTTP evidence proves successful command injection and root-level command execution in the responding workload, even though the responses were HTTP 400. The strongest event contains shell-command input and non-reflected process-identity output identifying UID 0 ([redacted]); another response disclosed non-reflected kernel information ([redacted]). Event-driven process telemetry independently shows root shells and discovery commands in the correlated workload, followed by sensitive-target and shared-resource activity. The detector's confirmed state and confirmed-compromise classification are therefore supported. Process timing does not establish a unique request-to-process edge, and no cited flow evidence was available to assess outbound consequences.