Live public case
Attempted exploitation
Last activity Aug 31, 7:05:16 AM PDT
Evidence-grounded assessment
Not required
A captured POST request triggered the immutable high-confidence command-injection-attempt detector for shell metacharacters with command tokens. The request received HTTP 301 with an empty response body, which neither proves nor disproves execution. No process or flow evidence is cited by this incident, so observed command execution or downstream network activity cannot be established. Evidence: HTTP event [redacted] (SHA-256 [redacted]).
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- No observed consequence is established; command execution, persistence, host escape, lateral movement, command-and-control, and data theft remain unproven.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Attempted exploitationopen
A captured POST request triggered the immutable high-confidence command-injection-attempt detector for shell metacharacters with command tokens. The request received HTTP 301 with an empty response body, which neither proves nor disproves execution. No process or flow evidence is cited by this incident, so observed command execution or downstream network activity cannot be established. Evidence: HTTP event [redacted] (SHA-256 [redacted]).