Live public case
Attempted exploitation
Last activity Aug 23, 3:29:46 AM PDT
Evidence-grounded assessment
Not required
The incident is best assessed as a likely true-positive command-injection attempt against target privatekind. The verified HTTP event records a POST whose request content triggered the high-confidence command-injection rule for shell metacharacters combined with command tokens. The request received a 301 response with an empty body in about 1 ms, but status and response shape do not establish whether execution succeeded or failed. No process or flow event is cited by the incident, so no execution, outbound connection, persistence, lateral movement, or data loss is established. This agrees with the detector's immutable output: the incident remains open and is classified as attempted exploitation, not confirmed compromise.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- A command-injection payload appears to have reached the HTTP gateway for target privatekind.
- No confirmed workload execution or post-exploitation impact is established by the available cited evidence.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Attempted exploitationopen
The incident is best assessed as a likely true-positive command-injection attempt against target privatekind. The verified HTTP event records a POST whose request content triggered the high-confidence command-injection rule for shell metacharacters combined with command tokens. The request received a 301 response with an empty body in about 1 ms, but status and response shape do not establish whether execution succeeded or failed. No process or flow event is cited by the incident, so no execution, outbound connection, persistence, lateral movement, or data loss is established. This agrees with the detector's immutable output: the incident remains open and is classified as attempted exploitation, not confirmed compromise.