Back to cases

Live public case

Observed workload execution

Last activity Sep 27, 9:21:16 AM PDT

criticalNot required

Evidence-grounded assessment

Not required

An event-driven discovery command was observed in a protected workload without correlated HTTP evidence

Protected workloads
Protected workload A
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Correlated process exited
  • Outbound client spawned
  • Sensitive file access command observed
  • Shared resource access observed
  • Shared resource execution observed
  • Shared resource mutation observed
  • Shell spawned
  • Workload discovery process spawned
  • Workload root shell

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Suspicious activityopen

      An event-driven discovery command was observed in a protected workload without correlated HTTP evidence