Back to cases

Live public case

Confirmed compromise

Last activity Aug 18, 11:18:15 PM PDT

highImpact confirmedResolved · Authorized test

Evidence-grounded assessment

Not required

The detector's immutable state is confirmed/confirmed_compromise, and the available evidence supports that conclusion. A command-injection-marked request received a response containing non-reflected kernel identification, proving command execution in the responding workload even though the HTTP status was 400 (HTTP [redacted]). Separate responses contained non-reflected root/UID 0 identity output (HTTP [redacted] and [redacted]). Correlated process telemetry independently observed root dash shells and root discovery commands in the workload window, but it does not provide a unique request-to-process causality edge (process [redacted], [redacted], [redacted]). No cited flow-plane evidence was available, so outbound communication, command-and-control, and exfiltration are not established.

Shared case lifecycle

Resolved · Authorized test

This read-only state comes from the same canonical workflow as the private operator console. Notes and append-only action history remain private.

Observed impact

  • Correlated process exited
  • Outbound client spawned
  • Remote command execution
  • Server identity disclosure
  • Shell spawned
  • System discovery
  • System information disclosure
  • Workload discovery process spawned
  • Workload root shell
  • Remote command execution was proven in the responding workload, with root/UID 0 execution identity disclosed (HTTP [redacted] and [redacted]).
  • Kernel and operating-system information was disclosed in server responses (HTTP [redacted] and [redacted]).
  • Root shell and discovery executables were observed in the correlated workload window; unique causality to a particular request remains unproven (process [redacted], [redacted], 39b5dd0d3cfde30bc2e

Recommended actions

    Attack timeline

    1 incident threads

    Resolution changes operator work, not the preserved attack evidence below.

    1. 1
      Confirmed compromiseconfirmed

      The detector's immutable state is confirmed/confirmed_compromise, and the available evidence supports that conclusion. A command-injection-marked request received a response containing non-reflected kernel identification, proving command execution in the responding workload even though the HTTP status was 400 (HTTP [redacted]). Separate responses contained non-reflected root/UID 0 identity output (HTTP [redacted] and [redacted]). Correlated process telemetry independently observed root dash shells and root discovery commands in the workload window, but it does not provide a unique request-to-process causality edge (process [redacted], [redacted], [redacted]). No cited flow-plane evidence was available, so outbound communication, command-and-control, and exfiltration are not established.