Back to evidence

Sanitized live incident

Attempted exploitation

Native source identity and targetable endpoints are private.

highopen
Confidence
88%
First seen
Aug 16, 6:24:39 PM PDT
Evidence through
Aug 16, 6:27:01 PM PDT
AI status
Outside window
AI investigation is Outside window

Deterministic signals remain live while the bounded assessment completes.

Observed impact

  • Sensitive file access command observed
  • Server identity disclosure
  • Shell spawned
  • Workload discovery process spawned
  • Workload root shell

Deterministic signals

Http.server command output85%

Response contains non-reflected process identity output

2 observations · 2 http
Http.command injection attempt88%

Request contains shell metacharacters and command tokens

3 observations · 3 http
Process.correlated discovery command72%

A discovery process appeared in the correlated workload and request window

4 observations · 4 process
Process.correlated shell spawn72%

A shell process appeared in the correlated workload and request window

14 observations · 12 process
Process.correlated sensitive file command72%

A process command targeted a sensitive file in the correlated workload and request window

1 observations · 1 process