Back to evidence

Sanitized live incident

Confirmed compromise

Native source identity and targetable endpoints are private.

criticalconfirmed
Confidence
100%
First seen
Aug 14, 7:01:23 PM PDT
Evidence through
Aug 14, 7:09:55 PM PDT
AI status
Outside window
AI investigation is Outside window

Deterministic signals remain live while the bounded assessment completes.

Observed impact

  • New outbound destination
  • Remote command execution
  • Root execution
  • Server identity disclosure

Deterministic signals

Http.command injection attempt88%

Request contains shell metacharacters and command tokens

4 observations · 4 http
Http.server command output100%

Exploit request received non-reflected process identity output

1 observations · 1 http
Flow.correlated new outbound destination70%

The correlated workload opened a flow to a destination not previously observed in the captured baseline

1 observations · 1 flow · 1 inventory