shared protected workload attribution and temporal proximity
Live public case
Confirmed compromise
Last activity Aug 28, 12:15:56 PM PDT
Evidence-grounded assessment
Likely same operation
The two immutable incident threads are best explained as related parts of one operational episode, but not conclusively one actor or one causal chain. Incident [redacted] records broad HTTP enumeration followed by confirmed command/root execution and related process behavior, while incident [redacted] records overlapping event-driven shell, outbound-client, and shared-resource activity. Deterministic link [redacted] ties them by protected-workload attribution and temporal proximity at 0.9 confidence. The overlap and compatible behaviors support likely_same_operation; the absence of a unique request-to-process edge and the workload-derived identity of the process-only thread prevent a definitive same_operation finding.
- Protected workloads
- Protected workload A · Protected workload B
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Confirmed root execution
- Correlated process exited
- Outbound client spawned
- Remote command execution
- Root execution
- Sensitive file access command observed
- Server identity disclosure
- Shared resource access observed
- Shared resource execution observed
- Shell spawned
- Workload discovery process spawned
- Workload root shell
- Confirmed remote command execution as root within the responding workload.
- Root shell and identity-discovery processes executed in correlated workloads.
- Root processes targeted a sensitive file; successful disclosure or theft of its contents is not established.
- Outbound-capable processes appeared, but no network flow was available to prove an outbound connection.
- Root shell processes executed inside the protected processor workload ([redacted], [redacted], [redacted], [redacted]).
- A root `dash` process was classified as an outbound-capable network client, but no network connection is proven ([redacted]).
- Execution from and access to shared resource [redacted] were observed, including root `cat` access ([redacted], [redacted], [redacted], 6af9849212cfffd2
- A sampled shell lifecycle exited nonzero; other sampled shell lifecycles exited zero ([redacted], [redacted], [redacted]).
Recommended actions
- Preserve the two incident boundaries and investigate them jointly under the likely-single-operation hypothesis without treating membership as actor attribution.
- Correlate available application, proxy, workload, and process-lineage telemetry around [redacted]–[redacted]56Z to seek a direct request-to-process edge.
- Validate whether the event-driven shells, outbound clients, and shared-resource access were expected administrative or workload behavior.
- Review the affected workloads and shared resource for scope, persistence, credential exposure, and unauthorized changes; apply containment proportionate to the confirmed root execution.
- Determine whether the enumerating traffic was authorized testing and whether the derived source cluster contains multiple workers or intermediary infrastructure.
Attack timeline
2 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Confirmed compromiseconfirmed
The detector's immutable state is confirmed with classification confirmed_compromise, and the evidence supports that result: an exploit request/response exchange returned non-reflected process identity output showing root/UID 0, proving command execution in the responding workload despite HTTP 400. Root shell and discovery executions, sensitive-file-targeting commands, and outbound-capable process activity were also observed in correlated workload/time windows. The evidence does not establish host escape, persistence, data theft, or actual outbound socket activity.
- 2Suspicious activityopen
The detector's critical suspicious-activity output is supported at the process-observation level: event-driven root `dash` executions occurred repeatedly, one was classified as both a shell and network client, and later root processes executed/accessed inventory-resolved shared resource [redacted] (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]; inventory evidence [redacted]). However, the bounded evidence exposes neither command arguments/content nor a causal originating action. No incident-cited HTTP or flow event was available to establish exploitation or an outbound connection. The same observations could reflect unauthorized execution or legitimate processor/administrative behavior, so compromise cannot be adjudicated from the available evidence.