Live public case
Confirmed compromise
Last activity Aug 18, 12:30:02 PM PDT
Evidence-grounded assessment
Likely same operation
The five preserved incident threads are most plausibly phases or repeated actions within one operation against the same target: broad reconnaissance, command-injection attempts, confirmed workload compromise, additional command/discovery activity, and a later injection attempt with a temporally correlated root shell. The incidents form an unbroken deterministic same-source-cluster chain across about 2.4 hours. This supports likely—not definitive—common operation because the source cluster may conceal a proxy, NAT, shared account, or multiple workers, and workload/time correlation does not establish unique request-to-process causality. Incident boundaries and detector classifications remain unchanged.
Shared case lifecycle
Resolved · Authorized test
This read-only state comes from the same canonical workflow as the private operator console. Notes and append-only action history remain private.
Observed impact
- Correlated process exited
- Outbound client spawned
- Remote command execution
- Root execution
- Sensitive file access command observed
- Server identity disclosure
- Shell spawned
- Workload discovery process spawned
- Workload root shell
- Potential disclosure of which routes exist, require authentication, reject methods, or return content; no verified post-reconnaissance impact is established.
- Potential arbitrary command execution against target privatekind if the receiving endpoint is vulnerable; no realized execution or downstream impact is demonstrated by HTTP event [redacted].
- The observed response contained zero bytes, so it provides no server-generated command output or other direct proof of execution [redacted].
- Remote command execution occurred in the responding workload with UID 0/root privileges [redacted].
- A root dash shell and its root id discovery child were observed in the correlated workload [redacted].
- A root cat process classified as targeting a sensitive resource was observed; the evidence does not establish what content was returned or removed [redacted].
- A separate injection attempt targeted the system account database [redacted].
- Server-side command execution disclosed root/UID 0 identity output ([redacted]).
- Root-context shell and identity-discovery processes executed in the workload ([redacted]; [redacted]).
- A root-context shell spawned cat with a sensitive target; command execution is observed, but successful file reading or disclosure is not established ([redacted]; [redacted]).
- An outbound-capable shell-class process executed as root and exited nonzero; no network connection is established by the available evidence ([redacted]; [redacted]).
- A dash shell executed as root in the correlated workload (PID 4135756) [redacted].
- The observed shell lifecycle later exited with outcome zero; this proves process completion, not HTTP-request causality [redacted].
Recommended actions
- Treat the sequence as a likely single active compromise investigation while preserving all five incident boundaries and their immutable detector classifications.
- Prioritize containment and forensic review of the affected privatekind workload because incident [redacted] contains confirmed-compromise evidence and later incidents show continuing suspicious activity.
- Review available request tracing, workload audit records, and parent-process telemetry to test the unresolved request-to-process links in incidents [redacted], [redacted], and [redacted].
- If retained telemetry exists, examine flow records for the interval 2026-08-18T17[redacted]56Z–[redacted]02Z to determine whether the observed outbound-client process established communications or transferred data.
- Determine whether the source cluster contains multiple distinguishable clients or authorized scanners before attributing all activity to one actor.
- Assess credentials, tokens, and secrets accessible to the compromised workload and rotate or revoke them proportionally if exposure cannot be excluded.
Attack timeline
5 incident threads
Resolution changes operator work, not the preserved attack evidence below.
- 1Reconnaissanceopen
The evidence supports the detector's reconnaissance finding: one derived source cluster sent a broad, rapid sequence of requests to target privatekind using multiple HTTP methods and distinct route hashes. Representative requests include GET, POST, and OPTIONS against API and other route categories, with varied 200/401/404/405/422 responses. This is consistent with automated surface and method enumeration. Authorization and source identity are unresolved, so the activity could be sanctioned testing or inventory rather than hostile reconnaissance. No process or flow evidence is cited by this incident, so no execution, persistence, lateral movement, outbound callback, or other post-reconnaissance consequence is established.
- 2Attempted exploitationopen
The captured HTTP transaction is consistent with an attempted command-injection attack: the complete 115-byte PUT request triggered the verified high-severity rule for shell metacharacters combined with command tokens. The request received HTTP 200 with an empty response, but status alone does not establish command execution. No cited process or flow evidence is available to demonstrate execution, outbound activity, persistence, or other post-exploitation consequences. Evidence: HTTP event [redacted] (SHA-256 [redacted]).
- 3Confirmed compromiseconfirmed
Incident [redacted] retains the detector's immutable confirmed/confirmed_compromise state. The verdict is independently supported by a command-injection request whose response contained non-reflected process-identity output and explicit command-input/process-output correlation showing UID 0/root (HTTP [redacted]). Root shell and discovery processes, plus a root sensitive-file tool, were also observed in the correlated workload (process [redacted], [redacted], [redacted]). The HTTP 400 responses do not negate execution because server-generated command output is present. Process timing/lineage corroborates workload activity but is not treated as a unique request-to-process causality edge.
- 4Attempted exploitationopen
Verified HTTP evidence shows server-generated, non-reflected root/UID 0 identity output, which establishes server-side execution even though that response was HTTP 400 ([redacted]). Two additional requests contained shell metacharacters with command tokens ([redacted]; [redacted]). Workload telemetry independently recorded root-context dash/id execution and, immediately after the later request, a root dash-to-cat lineage targeting a sensitive file ([redacted]; [redacted]; [redacted]; [redacted]). This supports successful command injection with root-context command execution and discovery, beyond the detector's attempted-exploitation classification. Request-to-process attribution remains temporal/workload-based rather than a unique trace edge.
- 5Attempted exploitationopen
The evidence strongly supports a genuine command-injection attempt against target privatekind: the verified HTTP event was flagged for shell metacharacters with command tokens [redacted]. About four seconds later, event-driven process telemetry recorded a root-run dash shell in the detector-correlated workload [redacted], and the same observed PID later exited with a zero outcome [redacted]. This materially strengthens the incident, but does not prove that this particular request created the shell because workload routing and temporal correlation are not a unique request-to-process edge. The HTTP 400 status does not itself establish success or failure. The immutable detector classification remains attempted_exploitation; the appropriate adjudication is likely true positive, with possible execution rather than conclusively request-attributed execution.