Live public case
Attempted exploitation
Last activity Aug 25, 12:14:32 AM PDT
Evidence-grounded assessment
Not required
The evidence supports a likely genuine exploitation attempt against target privatekind. After a detector-aggregated period of broad route/method enumeration, the same derived source cluster sent a PUT request whose captured 267-byte body triggered the command-injection rule for shell metacharacters with command tokens [http:[redacted]]. The request received HTTP 200 with an empty response body, but status alone neither proves nor disproves execution. No cited process or flow event was available to establish a workload consequence or a unique request-to-process/socket edge. The incident's immutable detector classification remains attempted_exploitation; this assessment agrees at the attempt level, not at the level of successful command execution.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- A command-injection payload was delivered to the target-facing HTTP service.
- No command execution, outbound connection, persistence, lateral movement, data access, or other workload impact is established by the cited evidence.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Attempted exploitationopen
The evidence supports a likely genuine exploitation attempt against target privatekind. After a detector-aggregated period of broad route/method enumeration, the same derived source cluster sent a PUT request whose captured 267-byte body triggered the command-injection rule for shell metacharacters with command tokens [http:[redacted]]. The request received HTTP 200 with an empty response body, but status alone neither proves nor disproves execution. No cited process or flow event was available to establish a workload consequence or a unique request-to-process/socket edge. The incident's immutable detector classification remains attempted_exploitation; this assessment agrees at the attempt level, not at the level of successful command execution.