Back to cases

Live public case

Confirmed compromise

Last activity Aug 17, 3:52:18 PM PDT

criticalImpact confirmed

Evidence-grounded assessment

Not required

True positive: successful command injection produced non-reflected process identity output showing root/UID 0 in the same captured HTTP transaction (HTTP [redacted]). The 400 response does not negate execution because the server response contained command output. Additional HTTP transactions also returned root identity output, and four root-owned dash shells were observed in correlated workload/time windows. Two new public-web TCP flows were also observed from an inventory-attributed workload, but they cannot be causally linked to a request or shell and their purpose is unknown. The detector's confirmed/confirmed_compromise state is therefore supported for compromise of the responding workload; evidence does not establish host escape, persistence, lateral movement, command-and-control, or data theft.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • New outbound destination
  • Remote command execution
  • Root execution
  • Server identity disclosure
  • Shell spawned
  • Workload root shell
  • Remote command execution occurred in the responding workload with root/UID 0 privileges.
  • The server disclosed process identity output identifying root execution.
  • Four root-owned dash shell processes were observed in correlated workload/time windows; unique request-to-process causality is not established.
  • Two new outbound TCP flows to public web destinations were observed from an inventory-attributed workload; their purpose and causal relationship to exploitation are unknown.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Confirmed compromiseconfirmed

      True positive: successful command injection produced non-reflected process identity output showing root/UID 0 in the same captured HTTP transaction (HTTP [redacted]). The 400 response does not negate execution because the server response contained command output. Additional HTTP transactions also returned root identity output, and four root-owned dash shells were observed in correlated workload/time windows. Two new public-web TCP flows were also observed from an inventory-attributed workload, but they cannot be causally linked to a request or shell and their purpose is unknown. The detector's confirmed/confirmed_compromise state is therefore supported for compromise of the responding workload; evidence does not establish host escape, persistence, lateral movement, command-and-control, or data theft.