Back to evidence

Sanitized live incident

Confirmed compromise

Native source identity and targetable endpoints are private.

highconfirmed
Confidence
97%
First seen
Sep 8, 11:51:12 AM PDT
Evidence through
Sep 8, 12:13:40 PM PDT
AI status
Pending
AI investigation is Pending

Deterministic signals remain live while the bounded assessment completes.

Observed impact

  • Remote command execution
  • State changing http activity after compromise
  • System discovery
  • System information disclosure

Deterministic signals

Http.surface enumeration92%

Broad unauthenticated route and HTTP method enumeration observed

139 observations · 12 http
Http.command injection attempt88%

Request contains shell metacharacters and command tokens

18 observations · 12 http
Http.server os release output96%

Response contains non-reflected operating-system release data

1 observations · 1 http
Http.server kernel output97%

Response contains non-reflected kernel identification

1 observations · 1 http
Http.state changing activity after compromise88%

A state-changing HTTP method was observed after confirmed workload compromise

1 observations · 1 http