Back to cases

Live public case

Confirmed compromise

Last activity Aug 28, 12:15:56 PM PDT

criticalImpact confirmed

Evidence-grounded assessment

Likely same operation

The two immutable incident threads are best explained as related parts of one operational episode, but not conclusively one actor or one causal chain. Incident [redacted] records broad HTTP enumeration followed by confirmed command/root execution and related process behavior, while incident [redacted] records overlapping event-driven shell, outbound-client, and shared-resource activity. Deterministic link [redacted] ties them by protected-workload attribution and temporal proximity at 0.9 confidence. The overlap and compatible behaviors support likely_same_operation; the absence of a unique request-to-process edge and the workload-derived identity of the process-only thread prevent a definitive same_operation finding.

Protected workloads
Protected workload A · Protected workload B
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Confirmed root execution
  • Correlated process exited
  • Outbound client spawned
  • Remote command execution
  • Root execution
  • Sensitive file access command observed
  • Server identity disclosure
  • Shared resource access observed
  • Shared resource execution observed
  • Shell spawned
  • Workload discovery process spawned
  • Workload root shell
  • Confirmed remote command execution as root within the responding workload.
  • Root shell and identity-discovery processes executed in correlated workloads.
  • Root processes targeted a sensitive file; successful disclosure or theft of its contents is not established.
  • Outbound-capable processes appeared, but no network flow was available to prove an outbound connection.
  • Root shell processes executed inside the protected processor workload ([redacted], [redacted], [redacted], [redacted]).
  • A root `dash` process was classified as an outbound-capable network client, but no network connection is proven ([redacted]).
  • Execution from and access to shared resource [redacted] were observed, including root `cat` access ([redacted], [redacted], [redacted], 6af9849212cfffd2
  • A sampled shell lifecycle exited nonzero; other sampled shell lifecycles exited zero ([redacted], [redacted], [redacted]).

Recommended actions

  1. Preserve the two incident boundaries and investigate them jointly under the likely-single-operation hypothesis without treating membership as actor attribution.
  2. Correlate available application, proxy, workload, and process-lineage telemetry around [redacted]–[redacted]56Z to seek a direct request-to-process edge.
  3. Validate whether the event-driven shells, outbound clients, and shared-resource access were expected administrative or workload behavior.
  4. Review the affected workloads and shared resource for scope, persistence, credential exposure, and unauthorized changes; apply containment proportionate to the confirmed root execution.
  5. Determine whether the enumerating traffic was authorized testing and whether the derived source cluster contains multiple workers or intermediary infrastructure.

Attack timeline

2 incident threads

Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

  1. 1
    Confirmed compromiseconfirmed

    The detector's immutable state is confirmed with classification confirmed_compromise, and the evidence supports that result: an exploit request/response exchange returned non-reflected process identity output showing root/UID 0, proving command execution in the responding workload despite HTTP 400. Root shell and discovery executions, sensitive-file-targeting commands, and outbound-capable process activity were also observed in correlated workload/time windows. The evidence does not establish host escape, persistence, data theft, or actual outbound socket activity.

  2. 2
    Suspicious activityopen

    The detector's critical suspicious-activity output is supported at the process-observation level: event-driven root `dash` executions occurred repeatedly, one was classified as both a shell and network client, and later root processes executed/accessed inventory-resolved shared resource [redacted] (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]; inventory evidence [redacted]). However, the bounded evidence exposes neither command arguments/content nor a causal originating action. No incident-cited HTTP or flow event was available to establish exploitation or an outbound connection. The same observations could reflect unauthorized execution or legitimate processor/administrative behavior, so compromise cannot be adjudicated from the available evidence.

Relationship reasoning

Shared workload time window90%

shared protected workload attribution and temporal proximity