Back to evidence

Sanitized live incident

Attempted exploitation

Native source identity and targetable endpoints are private.

highopen
Confidence
88%
First seen
Aug 18, 7:29:34 AM PDT
Evidence through
Aug 18, 7:31:59 AM PDT
AI status
Outside window
AI investigation is Outside window

Deterministic signals remain live while the bounded assessment completes.

Observed impact

  • Server identity disclosure

Deterministic signals

Http.server command output85%

Response contains non-reflected process identity output

3 observations · 3 http
Http.command injection attempt88%

Request contains shell metacharacters and command tokens

2 observations · 2 http