Back to cases

Live public case

Observed workload execution

Last activity Aug 28, 2:37:48 AM PDT

highNot required

Evidence-grounded assessment

Not required

The incident is a true positive for successful command injection, not merely an attempt. Repeated malicious HTTP inputs were observed, including one targeting the system account database [[redacted]]. A captured HTTP response contained non-reflected server-generated identity output identifying UID 0/root even though the response status was 400 [[redacted]]; status therefore does not negate execution. Independent process telemetry recorded root shells, discovery, a sensitive-file command, and mutation/execution of the same shared resource in correlated workload contexts [redacted]. The HTTP-to-process relationship remains temporal/workload correlation rather than a unique per-request parentage edge, but the server-generated output directly establishes server-side root execution.

Protected workloads
Protected workload A · Protected workload B
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Correlated process exited
  • Sensitive file access command observed
  • Server identity disclosure
  • Shared resource execution observed
  • Shared resource mutation observed
  • Shell spawned
  • Workload discovery process spawned
  • Workload root shell
  • Server-side execution as UID 0/root was disclosed in captured HTTP output [[redacted]].
  • Root shell and discovery activity was observed in correlated workloads [redacted].
  • The same inventory-resolved shared resource was classified as mutated in one workload context and executed in another [redacted].
  • A root cat process targeted a sensitive file and its matched lifecycle exited zero; this establishes command completion but not data exfiltration [redacted].

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Attempted exploitationopen

      The incident is a true positive for successful command injection, not merely an attempt. Repeated malicious HTTP inputs were observed, including one targeting the system account database [[redacted]]. A captured HTTP response contained non-reflected server-generated identity output identifying UID 0/root even though the response status was 400 [[redacted]]; status therefore does not negate execution. Independent process telemetry recorded root shells, discovery, a sensitive-file command, and mutation/execution of the same shared resource in correlated workload contexts [redacted]. The HTTP-to-process relationship remains temporal/workload correlation rather than a unique per-request parentage edge, but the server-generated output directly establishes server-side root execution.