Live public case
Confirmed compromise
Last activity Aug 17, 3:52:18 PM PDT
Evidence-grounded assessment
Not required
True positive: successful command injection produced non-reflected process identity output showing root/UID 0 in the same captured HTTP transaction (HTTP [redacted]). The 400 response does not negate execution because the server response contained command output. Additional HTTP transactions also returned root identity output, and four root-owned dash shells were observed in correlated workload/time windows. Two new public-web TCP flows were also observed from an inventory-attributed workload, but they cannot be causally linked to a request or shell and their purpose is unknown. The detector's confirmed/confirmed_compromise state is therefore supported for compromise of the responding workload; evidence does not establish host escape, persistence, lateral movement, command-and-control, or data theft.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- New outbound destination
- Remote command execution
- Root execution
- Server identity disclosure
- Shell spawned
- Workload root shell
- Remote command execution occurred in the responding workload with root/UID 0 privileges.
- The server disclosed process identity output identifying root execution.
- Four root-owned dash shell processes were observed in correlated workload/time windows; unique request-to-process causality is not established.
- Two new outbound TCP flows to public web destinations were observed from an inventory-attributed workload; their purpose and causal relationship to exploitation are unknown.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Confirmed compromiseconfirmed
True positive: successful command injection produced non-reflected process identity output showing root/UID 0 in the same captured HTTP transaction (HTTP [redacted]). The 400 response does not negate execution because the server response contained command output. Additional HTTP transactions also returned root identity output, and four root-owned dash shells were observed in correlated workload/time windows. Two new public-web TCP flows were also observed from an inventory-attributed workload, but they cannot be causally linked to a request or shell and their purpose is unknown. The detector's confirmed/confirmed_compromise state is therefore supported for compromise of the responding workload; evidence does not establish host escape, persistence, lateral movement, command-and-control, or data theft.