Live public case
Confirmed compromise
Last activity Aug 18, 11:18:15 PM PDT
Evidence-grounded assessment
Not required
The detector's immutable state is confirmed/confirmed_compromise, and the available evidence supports that conclusion. A command-injection-marked request received a response containing non-reflected kernel identification, proving command execution in the responding workload even though the HTTP status was 400 (HTTP [redacted]). Separate responses contained non-reflected root/UID 0 identity output (HTTP [redacted] and [redacted]). Correlated process telemetry independently observed root dash shells and root discovery commands in the workload window, but it does not provide a unique request-to-process causality edge (process [redacted], [redacted], [redacted]). No cited flow-plane evidence was available, so outbound communication, command-and-control, and exfiltration are not established.
Shared case lifecycle
Resolved · Authorized test
This read-only state comes from the same canonical workflow as the private operator console. Notes and append-only action history remain private.
Observed impact
- Correlated process exited
- Outbound client spawned
- Remote command execution
- Server identity disclosure
- Shell spawned
- System discovery
- System information disclosure
- Workload discovery process spawned
- Workload root shell
- Remote command execution was proven in the responding workload, with root/UID 0 execution identity disclosed (HTTP [redacted] and [redacted]).
- Kernel and operating-system information was disclosed in server responses (HTTP [redacted] and [redacted]).
- Root shell and discovery executables were observed in the correlated workload window; unique causality to a particular request remains unproven (process [redacted], [redacted], 39b5dd0d3cfde30bc2e
Recommended actions
Attack timeline
1 incident threads
Resolution changes operator work, not the preserved attack evidence below.
- 1Confirmed compromiseconfirmed
The detector's immutable state is confirmed/confirmed_compromise, and the available evidence supports that conclusion. A command-injection-marked request received a response containing non-reflected kernel identification, proving command execution in the responding workload even though the HTTP status was 400 (HTTP [redacted]). Separate responses contained non-reflected root/UID 0 identity output (HTTP [redacted] and [redacted]). Correlated process telemetry independently observed root dash shells and root discovery commands in the workload window, but it does not provide a unique request-to-process causality edge (process [redacted], [redacted], [redacted]). No cited flow-plane evidence was available, so outbound communication, command-and-control, and exfiltration are not established.