Back to cases

Live public case

Attempted exploitation

Last activity Aug 31, 7:05:16 AM PDT

highNot required

Evidence-grounded assessment

Not required

A captured POST request triggered the immutable high-confidence command-injection-attempt detector for shell metacharacters with command tokens. The request received HTTP 301 with an empty response body, which neither proves nor disproves execution. No process or flow evidence is cited by this incident, so observed command execution or downstream network activity cannot be established. Evidence: HTTP event [redacted] (SHA-256 [redacted]).

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • No observed consequence is established; command execution, persistence, host escape, lateral movement, command-and-control, and data theft remain unproven.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Attempted exploitationopen

      A captured POST request triggered the immutable high-confidence command-injection-attempt detector for shell metacharacters with command tokens. The request received HTTP 301 with an empty response body, which neither proves nor disproves execution. No process or flow evidence is cited by this incident, so observed command execution or downstream network activity cannot be established. Evidence: HTTP event [redacted] (SHA-256 [redacted]).