Sanitized live incident
Attempted exploitation
Native source identity and targetable endpoints are private.
highopen
- Confidence
- 88%
- First seen
- Aug 13, 9:52:27 PM PDT
- Evidence through
- Aug 13, 10:37:03 PM PDT
- AI status
- Outside window
AI investigation is Outside window
Deterministic signals remain live while the bounded assessment completes.
Observed impact
- New outbound destination
- Server identity disclosure
- Shell spawned
- System information disclosure
- Workload discovery process spawned
- Workload root shell
Deterministic signals
Response contains non-reflected process identity output
7 observations · 7 httpResponse contains non-reflected kernel identification
2 observations · 2 httpThe correlated workload opened a flow to a destination not previously observed in the captured baseline
1 observations · 1 flow · 1 inventoryA shell process appeared in the correlated workload and request window
13 observations · 12 processA discovery process appeared in the correlated workload and request window
7 observations · 7 processRequest contains shell metacharacters and command tokens
8 observations · 8 http