Live public case
Attempted exploitation
Last activity Aug 16, 6:27:01 PM PDT
highNot required
Evidence-grounded assessment
Not required
Response contains non-reflected process identity output
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Sensitive file access command observed
- Server identity disclosure
- Shell spawned
- Workload discovery process spawned
- Workload root shell
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Attempted exploitationopen
Response contains non-reflected process identity output