Live evidence workspace
Evidence
Sanitized incident threads, signals, evidence planes, and AI conclusions update continuously.
This is a true positive for opportunistic reconnaissance: the detector recorded a rapid cluster of 39 GET requests spanning 20 PHP/WordPress probe paths against target privatekind. Verified HTTP samples at the beginning and end of the burst are categorized as php_or_wordpress_probe and received 301 or 404 responses [[redacted], [redacted], [redacted], [redacted]]. The evidence establishes enumeration activity, but not successful exploitation. HTTP status is not dispositive, response-content semantics were not exposed, and the incident cites no process or flow events with which to evaluate execution or outbound consequences.
Verified event-driven process telemetry shows repeated root-run dash shells in the protected workload, including child discovery utilities and a root-run cat process classified as targeting a sensitive file. This strongly supports unauthorized or attack-like command execution with discovery and sensitive-file access activity. However, no HTTP or flow evidence references are available to establish the initiating action, actor, exploit vector, request-to-process causality, network consequence, or whether the activity was authorized administration or lab automation.
The evidence establishes successful server-side command execution, not merely an attempt. Three captured HTTP responses contained non-reflected process-identity output identifying root/UID 0 despite HTTP 400 statuses ([redacted], [redacted], [redacted]). Event-driven telemetry in the correlated workload also recorded root dash shells and child discovery/sensitive-file processes ([redacted], [redacted], [redacted], [redacted]). HTTP requests with shell metacharacters and command tokens occurred in the same time windows ([redacted], [redacted]). The evidence does not provide a unique request-to-process trace edge, prove sensitive-file contents were returned, or prove an outbound connection.
Likely true positive for suspicious in-workload execution, but not proof of a remote exploit. Event-driven telemetry shows repeated root-run dash executions, including discovery-classified activity, plus a root-run cat child targeting a sensitive file [redacted]. Exact lifecycle evidence shows the sensitive-targeting shell and cat exited nonzero, while other discovery/shell instances exited zero [redacted]. No cited HTTP or flow events were available to establish origin, request causality, actor identity, egress, or exploitation.
This is a true positive for rapid, opportunistic PHP/WordPress web-shell path enumeration, not a demonstrated compromise. The incident aggregates 331 requests across 167 unique probe paths from one derived source cluster over approximately 12 seconds, and the bounded HTTP evidence confirms GET requests categorized as PHP/WordPress probes [[redacted], [redacted], [redacted], [redacted]]. The incident reports redirect/rejection-only outcomes for all 331 requests, with cited summaries showing 301 or 404 responses [[redacted], [redacted], [redacted], [redacted]]. No process- or flow-plane evidence is cited, so the available evidence does not establish command execution, outbound activity, persistence, or other post-exploitation impact.
Likely true positive for automated, unauthenticated web-surface reconnaissance against target privatekind. The aggregate volume, near one-to-one request/path ratio, rapid timing, varied route categories, and representative PHP/WordPress probing strongly support route enumeration rather than ordinary browsing. Authorization cannot be established, so the activity could still be an approved scanner. The incident cites no process or flow evidence establishing exploitation or downstream workload consequences.
The detector's immutable state is confirmed/confirmed_compromise, and the available evidence supports that conclusion. A command-injection-marked request received a response containing non-reflected kernel identification, proving command execution in the responding workload even though the HTTP status was 400 (HTTP [redacted]). Separate responses contained non-reflected root/UID 0 identity output (HTTP [redacted] and [redacted]). Correlated process telemetry independently observed root dash shells and root discovery commands in the workload window, but it does not provide a unique request-to-process causality edge (process [redacted], [redacted], [redacted]). No cited flow-plane evidence was available, so outbound communication, command-and-control, and exfiltration are not established.
Likely true positive for suspicious workload execution: event-driven telemetry directly observed multiple root-context dash shells, a root-context bash child shell, and root-context discovery executables (`id` and `hostname`) in one workload (process evidence [redacted], [redacted], [redacted], [redacted], [redacted]). This supports execution and discovery inside the workload, but not exploitation, remote-request causality, persistence, host escape, or data theft. The origin and authorization remain unresolved because no incident-cited HTTP or flow evidence was available.
Verified process telemetry supports a likely true positive for suspicious execution and discovery inside the workload: event-driven root-context dash shells ran, and root-context id and hostname discovery processes were observed beneath shell lineage [redacted]. Exact matching exit telemetry shows sampled shell/discovery processes exited with zero outcomes, but that does not determine whether the activity was authorized or tie it to any HTTP request [redacted]. No incident-cited HTTP or flow events were available through the respective evidence tools, so exploitation origin, actor, and network consequences remain unproven.
The incident is a true positive for opportunistic PHP/WordPress web-shell path enumeration, not for confirmed compromise. The source traffic cluster generated a rapid series of GET probes across many PHP/WordPress-associated paths. The incident aggregate records 214 requests against 109 unique probe paths in about 40 seconds, with all 214 classified as rejected responses. Verified representative requests returned only 301 redirects or 404 responses. No process- or flow-plane event references are cited by this incident, so execution, persistence, or outbound activity cannot be adjudicated from those planes and is not claimed.
The evidence strongly supports real automated HTTP surface enumeration against target privatekind from one derived traffic cluster. The detector aggregated 356 requests spanning 173 unique paths, six methods, and eight path categories; verified samples show rapid POST, PATCH, PUT, and GET activity against distinct path hashes, with a mixture of 200, 404, 405, and 422 responses. This is highly consistent with reconnaissance, but maliciousness is not conclusive because authorization and source ownership are unknown and the incident also reports substantial authenticated traffic. Some requests returned 200, but status codes and body hashes alone do not prove state change, exploitation, or compromise. No cited process or flow events were available to assess downstream consequences.
The reviewed HTTP evidence supports the detector's finding of automated surface enumeration against target privatekind: one traffic cluster issued GET and HEAD requests across distinct hashed paths and categories, receiving a mixture of 200, 401, 404, and 405 responses (for example, [redacted], [redacted], [redacted], [redacted], and [redacted]). This is likely genuine reconnaissance, but whether it was unauthorized or malicious cannot be determined from network evidence. No process or flow event identities are cited by the incident, so downstream execution or network consequences cannot be assessed.
The evidence strongly supports a genuine command-injection attempt against target privatekind: the verified HTTP event was flagged for shell metacharacters with command tokens [redacted]. About four seconds later, event-driven process telemetry recorded a root-run dash shell in the detector-correlated workload [redacted], and the same observed PID later exited with a zero outcome [redacted]. This materially strengthens the incident, but does not prove that this particular request created the shell because workload routing and temporal correlation are not a unique request-to-process edge. The HTTP 400 status does not itself establish success or failure. The immutable detector classification remains attempted_exploitation; the appropriate adjudication is likely true positive, with possible execution rather than conclusively request-attributed execution.
Direct event-driven process telemetry supports real suspicious activity inside the workload: a root-run dash process classified as both shell and discovery spawned a root-run env child [redacted], similar root shell/discovery executions recurred later [redacted], and a root-run dash process classified as a shell and sensitive-file tool targeted a sensitive resource [redacted]. This makes the behavioral detection likely valid, but available evidence does not identify the initiating actor or distinguish malicious execution from authorized administrative/lab automation. No HTTP or flow evidence references were available to establish an ingress vector or network consequence.
Likely true positive for suspicious root-level command execution inside the workload, but not proof of external exploitation. Event-driven process evidence shows a root dash shell spawning discovery command id [redacted], later followed by a root dash/head chain classified as targeting a sensitive file [redacted]. Additional root dash executions continued through [redacted]36Z [redacted]. The repeated shell, discovery, and sensitive-file pattern strongly supports genuine suspicious activity. However, no HTTP or flow references are available to identify an initiating request or network consequence, and authorization or lab activity cannot be excluded.
Verified HTTP evidence shows server-generated, non-reflected root/UID 0 identity output, which establishes server-side execution even though that response was HTTP 400 ([redacted]). Two additional requests contained shell metacharacters with command tokens ([redacted]; [redacted]). Workload telemetry independently recorded root-context dash/id execution and, immediately after the later request, a root dash-to-cat lineage targeting a sensitive file ([redacted]; [redacted]; [redacted]; [redacted]). This supports successful command injection with root-context command execution and discovery, beyond the detector's attempted-exploitation classification. Request-to-process attribution remains temporal/workload-based rather than a unique trace edge.
Incident [redacted] retains the detector's immutable confirmed/confirmed_compromise state. The verdict is independently supported by a command-injection request whose response contained non-reflected process-identity output and explicit command-input/process-output correlation showing UID 0/root (HTTP [redacted]). Root shell and discovery processes, plus a root sensitive-file tool, were also observed in the correlated workload (process [redacted], [redacted], [redacted]). The HTTP 400 responses do not negate execution because server-generated command output is present. Process timing/lineage corroborates workload activity but is not treated as a unique request-to-process causality edge.
Verified process telemetry establishes three root-context dash shell executions, each followed by a root-context id discovery process in the same workload (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). Exact lifecycle evidence shows all six processes exited; the first pair had nonzero outcomes and the later four had zero outcomes (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). This supports execution and discovery inside the workload, but not a malicious origin: the incident cites no HTTP or flow events, and the available summaries omit command arguments and authorization context. The detector's critical suspicious-activity output remains intact, while the available evidence is insufficient to distinguish exploitation from legitimate administrative or workload behavior.
The captured HTTP transaction is consistent with an attempted command-injection attack: the complete 115-byte PUT request triggered the verified high-severity rule for shell metacharacters combined with command tokens. The request received HTTP 200 with an empty response, but status alone does not establish command execution. No cited process or flow evidence is available to demonstrate execution, outbound activity, persistence, or other post-exploitation consequences. Evidence: HTTP event [redacted] (SHA-256 [redacted]).
The evidence supports the detector's reconnaissance finding: one derived source cluster sent a broad, rapid sequence of requests to target privatekind using multiple HTTP methods and distinct route hashes. Representative requests include GET, POST, and OPTIONS against API and other route categories, with varied 200/401/404/405/422 responses. This is consistent with automated surface and method enumeration. Authorization and source identity are unresolved, so the activity could be sanctioned testing or inventory rather than hostile reconnaissance. No process or flow evidence is cited by this incident, so no execution, persistence, lateral movement, outbound callback, or other post-reconnaissance consequence is established.
Response contains non-reflected process identity output
Response contains non-reflected process identity output
Rapid enumeration of PHP and WordPress web-shell paths
Rapid enumeration of PHP and WordPress web-shell paths
Rapid enumeration of PHP and WordPress web-shell paths
Response contains non-reflected process identity output
Response contains non-reflected process identity output
Request contains shell metacharacters and command tokens
Rapid enumeration of PHP and WordPress web-shell paths
Request contains shell metacharacters and command tokens
Response contains non-reflected process identity output
Response contains non-reflected process identity output
True positive: successful command injection produced non-reflected process identity output showing root/UID 0 in the same captured HTTP transaction (HTTP [redacted]). The 400 response does not negate execution because the server response contained command output. Additional HTTP transactions also returned root identity output, and four root-owned dash shells were observed in correlated workload/time windows. Two new public-web TCP flows were also observed from an inventory-attributed workload, but they cannot be causally linked to a request or shell and their purpose is unknown. The detector's confirmed/confirmed_compromise state is therefore supported for compromise of the responding workload; evidence does not establish host escape, persistence, lateral movement, command-and-control, or data theft.
Request contains shell metacharacters and command tokens
Request contains shell metacharacters and command tokens
Rapid enumeration of PHP and WordPress web-shell paths
Request contains shell metacharacters and command tokens
Request contains shell metacharacters and command tokens
Rapid enumeration of PHP and WordPress web-shell paths
Rapid enumeration of PHP and WordPress web-shell paths
Request contains shell metacharacters and command tokens
Response contains non-reflected process identity output
Rapid enumeration of PHP and WordPress web-shell paths
Request contains shell metacharacters and command tokens
Rapid enumeration of PHP and WordPress web-shell paths
Request contains shell metacharacters and command tokens
Rapid enumeration of PHP and WordPress web-shell paths
Rapid enumeration of PHP and WordPress web-shell paths
Rapid enumeration of PHP and WordPress web-shell paths
Request contains shell metacharacters and command tokens
Rapid enumeration of PHP and WordPress web-shell paths
Rapid enumeration of PHP and WordPress web-shell paths
Rapid enumeration of PHP and WordPress web-shell paths
Rapid enumeration of PHP and WordPress web-shell paths
Request contains shell metacharacters and command tokens
Request contains shell metacharacters and command tokens
Request contains shell metacharacters and command tokens
Request contains shell metacharacters and command tokens
Request contains shell metacharacters and command tokens
Rapid enumeration of PHP and WordPress web-shell paths
Request contains shell metacharacters and command tokens
Rapid enumeration of PHP and WordPress web-shell paths
Exploit request received non-reflected process identity output
Request contains shell metacharacters and command tokens
Response contains non-reflected process identity output
Request contains shell metacharacters and command tokens
Request contains shell metacharacters and command tokens
Request contains shell metacharacters and command tokens
Rapid enumeration of PHP and WordPress web-shell paths
Request contains shell metacharacters and command tokens