Sanitized live incident
Attempted exploitation
Native source identity and targetable endpoints are private.
highopen
- Confidence
- 88%
- First seen
- Aug 17, 12:07:30 PM PDT
- Evidence through
- Aug 17, 12:39:04 PM PDT
- AI status
- Outside window
AI investigation is Outside window
Deterministic signals remain live while the bounded assessment completes.
Observed impact
- Sensitive file access command observed
- Server identity disclosure
- Shell spawned
- Workload discovery process spawned
- Workload root shell
Deterministic signals
Request contains shell metacharacters and command tokens
14 observations · 12 httpResponse contains non-reflected process identity output
2 observations · 2 httpA shell process appeared in the correlated workload and request window
17 observations · 12 processA discovery process appeared in the correlated workload and request window
8 observations · 8 processA process command targeted a sensitive file in the correlated workload and request window
1 observations · 1 process