Back to cases

Live public case

Confirmed compromise

Last activity Aug 21, 5:18:53 PM PDT

criticalImpact confirmed

Evidence-grounded assessment

Likely same operation

The strongest defensible explanation is one likely operation conducted in two waves against the same target. Both confirmed HTTP incidents show enumeration followed by proven root command execution and share a privacy-preserving source cluster [redacted]. Root-shell, discovery, sensitive-file, and shared-resource process incidents fall within the corresponding workload windows. This supports a likely common operation, but the deterministic links do not establish one actor or unique HTTP-request-to-process causality.

Protected workloads
Protected workload A · Protected workload B
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Confirmed root execution
  • Correlated process exited
  • Outbound client spawned
  • Remote command execution
  • Sensitive file access command observed
  • Server identity disclosure
  • Shared resource access observed
  • Shared resource execution observed
  • Shared resource mutation observed
  • Shell spawned
  • System discovery
  • System information disclosure
  • Workload discovery process spawned
  • Workload root shell
  • Root-level command execution occurred in the responding application workload (HTTP evidence [redacted] and [redacted]).
  • Kernel and operating-system information was disclosed to the requester (HTTP evidence [redacted]).
  • A root shell and child cat process targeted a sensitive file; successful file disclosure is not established (process evidence [redacted] and [redacted]).
  • Outbound-capable root shell processes were spawned, but no network connection or data transfer is proven (process evidence [redacted] and [redacted]).
  • A root-run shell process was observed in the protected workload.
  • The process was classified as a sensitive-file tool with a sensitive target; actual read, disclosure, or modification of file contents is not established.
  • The observed process exited with outcome zero; no persistence, host escape, lateral movement, command-and-control, or data theft is demonstrated.
  • Two root-context dash shell processes executed in the protected workload (process evidence [redacted] and [redacted]).
  • No further security consequence is established by the available cited evidence.
  • A root shell-class process targeting a sensitive file was observed inside the workload [redacted].
  • The observed process exited with a zero outcome; this indicates lifecycle completion but does not by itself prove what data was read or any downstream compromise [redacted].
  • Two root-context dash shell processes executed in the protected workload [redacted].
  • No further consequence is established by the cited evidence.
  • Root-level dash shell processes executed in the workload [redacted].
  • Root-level discovery utilities id and env executed as child processes in sampled sequences [redacted].
  • Sampled shell/discovery processes exited successfully; this proves completion of those process lifecycles, not malicious impact [process:[redacted], process:[redacted], process:286e54329802ab720c3
  • claims malformed? Oops JSON likely invalid because truncated accidental. Need rewrite call only once not yet executed because malformed in analysis? It is tool call shown pending? Actually content invalid string maybe tool invocation parser
  • Root-level command execution was disclosed in server responses [[redacted], [redacted]].
  • Kernel/system discovery output was returned by the responding workload [[redacted]].
  • Root process telemetry observed discovery and sensitive-file tooling [redacted].
  • Execution and mutation of an inventory-resolved resource shared by multiple workloads were observed [redacted].
  • Root shell processes executed inside the protected processor workload.
  • A root discovery process (id) was spawned.
  • A root shell command targeted a sensitive file; actual disclosure is not established.
  • A shared resource was executed and accessed by root processes, creating potential cross-workload exposure if the activity was unauthorized.
  • Observed initial shell/discovery lifecycles exited successfully; this does not establish benign intent.
  • Root-level shell activity occurred in the workload [redacted].
  • A root cat process classified as targeting a sensitive file executed and exited zero; actual content exposure is not established [redacted].
  • A root shell classified as discovery was spawned; its precise discovery action and result are unavailable [redacted].

Recommended actions

  1. Preserve all incident boundaries and investigate the two confirmed HTTP waves together while retaining the same-source caveat [redacted].
  2. Review authorized-testing and administrative records for both windows before attributing intent or actor identity [redacted].
  3. Prioritize containment and forensic review of the affected workloads because root execution is confirmed, while avoiding unsupported claims of persistence or exfiltration [redacted].
  4. Seek request, process-lineage, and network-flow telemetry that could resolve the currently non-unique causality relationships documented by the shared-workload links.

Attack timeline

9 incident threads

Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

  1. 1
    Confirmed compromiseconfirmed

    Confirmed command-injection compromise of the responding workload. HTTP responses contained non-reflected root identity output despite HTTP 400 responses ([redacted]; [redacted]), and another injected request returned non-reflected kernel and OS-release data ([redacted]). Event-driven telemetry independently observed root dash processes and discovery children in the correlated workload ([redacted]; [redacted]; [redacted]; [redacted]). This validates the detector's immutable confirmed state for workload-level root execution, while not proving host escape, persistence, or request-to-process causality.

  2. 2
    Suspicious activityopen

    High-integrity process telemetry confirms that a root-run `dash` execution occurred and was classified both as a shell and a sensitive-file tool with a sensitive target. The same PID then exited with outcome zero. This establishes suspicious execution and a sensitive-file command, but not malicious intent, exploitation, or successful access to file contents. No HTTP or flow evidence references are available in the incident to establish an originating request, actor, network consequence, or request-to-process/socket causality. The activity could therefore be unauthorized execution or legitimate workload/administrative behavior.

  3. 3
    Suspicious activityopen

    Two event-driven process records prove that separate dash shell processes executed as root in the same protected workload within about 177 ms (process evidence [redacted] and [redacted]). This validates the detector's observed shell-spawn consequence, but the available summaries do not expose commands, parent identities, initiating action, or a causal HTTP/flow chain. Root dash execution can represent either malicious command execution or legitimate workload/administrative automation, so exploitation or compromise cannot be adjudicated from the cited evidence.

  4. 4
    Suspicious activityopen

    A root-run dash process was directly observed in the protected processor workload and classified as both a shell and a sensitive-file tool with a sensitive target [redacted]. The same PID then exited with a zero outcome [redacted]. This validates the detector's suspicious process observations, but the bounded evidence does not expose the command, target, actor, or initiating action, and there is no cited HTTP or flow event available to establish exploitation, network consequence, or malicious intent. Legitimate workload or administrative execution therefore remains plausible.

  5. 5
    Suspicious activityopen

    Two distinct event-driven executions of the dash shell as root were directly observed in the same protected workload within about 159 ms [redacted]. This validates the detector's shell-spawn observation, but the available summaries expose neither command arguments nor sufficient parent context to determine purpose. The incident cites no HTTP or flow events that can be inspected, so exploitation, an originating actor/action, and network consequences cannot be established. The activity is therefore security-relevant but of indeterminate maliciousness.

  6. 6
    Suspicious activityopen

    Verified process telemetry establishes repeated root-level shell and discovery execution in the protected workload, including dash spawning id and dash spawning env, with exact zero-exit lifecycle evidence for sampled sequences [redacted]. This confirms execution and discovery consequences, but not unauthorized exploitation. No incident-cited HTTP or flow events were available for bounded inspection, and the process summaries do not establish the initiating action, actor, or authorization. The behavior could represent malicious post-exploitation or legitimate processor/administrative activity; the available evidence cannot distinguish them.

  7. 7
    Confirmed compromiseconfirmed

    The detector’s immutable output is confirmed/confirmed_compromise, and the evidence supports that result. Command-injection-shaped HTTP requests were followed by responses containing non-reflected root identity and kernel output; notably, command output was present even in HTTP 400 responses, which proves execution in the responding workload rather than failure based on status alone [[redacted], [redacted], [redacted]]. Event-driven telemetry independently observed root dash shells, discovery utilities, sensitive-file tools, and shared-resource mutation in correlated workload windows [redacted]. This establishes successful remote command execution and post-exploitation activity within responding workloads. It does not establish host escape, persistence, exfiltration, lateral movement, or command-and-control.

  8. 8
    Suspicious activityopen

    The process activity is genuine and security-relevant: event-driven root dash executions occurred in the processor workload, an id discovery child was spawned, a later root shell targeted a sensitive file, and root processes executed and accessed a shared resource. However, the bounded evidence does not establish whether these actions were unauthorized or expected processor/administrative behavior. No usable HTTP or flow evidence was available to identify an originating action, actor, or network consequence. Accordingly, this is an indeterminate suspicious-execution incident rather than proven exploitation or compromise.

  9. 9
    Suspicious activityopen

    Likely true positive for suspicious privileged process activity inside the image-host workload, but not proof of an external exploit. Event-driven telemetry directly observed a root dash shell spawning a root cat process classified as targeting a sensitive file; both had exact, zero-outcome exits [redacted]. Additional root dash shells recurred from the same parent, and a later root dash execution was classified as discovery [redacted]. The available summaries do not expose command arguments, the sensitive target, authorization context, HTTP causality, or network consequences, so compromise scope and origin remain unresolved.

Relationship reasoning

Same source cluster86%

same privacy-preserving traffic source cluster and target within a bounded time window

Shared workload time window90%

shared protected workload attribution and temporal proximity

Shared workload time window90%

shared protected workload attribution and temporal proximity

Shared workload time window90%

shared protected workload attribution and temporal proximity

Shared workload time window90%

shared protected workload attribution and temporal proximity

Shared workload time window90%

shared protected workload attribution and temporal proximity

Shared workload time window90%

shared protected workload attribution and temporal proximity

Shared workload time window90%

shared protected workload attribution and temporal proximity