Live public case
Observed workload execution
Last activity Aug 28, 2:37:48 AM PDT
Evidence-grounded assessment
Not required
The incident is a true positive for successful command injection, not merely an attempt. Repeated malicious HTTP inputs were observed, including one targeting the system account database [[redacted]]. A captured HTTP response contained non-reflected server-generated identity output identifying UID 0/root even though the response status was 400 [[redacted]]; status therefore does not negate execution. Independent process telemetry recorded root shells, discovery, a sensitive-file command, and mutation/execution of the same shared resource in correlated workload contexts [redacted]. The HTTP-to-process relationship remains temporal/workload correlation rather than a unique per-request parentage edge, but the server-generated output directly establishes server-side root execution.
- Protected workloads
- Protected workload A · Protected workload B
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Correlated process exited
- Sensitive file access command observed
- Server identity disclosure
- Shared resource execution observed
- Shared resource mutation observed
- Shell spawned
- Workload discovery process spawned
- Workload root shell
- Server-side execution as UID 0/root was disclosed in captured HTTP output [[redacted]].
- Root shell and discovery activity was observed in correlated workloads [redacted].
- The same inventory-resolved shared resource was classified as mutated in one workload context and executed in another [redacted].
- A root cat process targeted a sensitive file and its matched lifecycle exited zero; this establishes command completion but not data exfiltration [redacted].
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Attempted exploitationopen
The incident is a true positive for successful command injection, not merely an attempt. Repeated malicious HTTP inputs were observed, including one targeting the system account database [[redacted]]. A captured HTTP response contained non-reflected server-generated identity output identifying UID 0/root even though the response status was 400 [[redacted]]; status therefore does not negate execution. Independent process telemetry recorded root shells, discovery, a sensitive-file command, and mutation/execution of the same shared resource in correlated workload contexts [redacted]. The HTTP-to-process relationship remains temporal/workload correlation rather than a unique per-request parentage edge, but the server-generated output directly establishes server-side root execution.