Sanitized live incident
Confirmed compromise
Native source identity and targetable endpoints are private.
criticalconfirmed
- Confidence
- 100%
- First seen
- Aug 14, 9:40:37 AM PDT
- Evidence through
- Aug 14, 11:44:05 AM PDT
- AI status
- Outside window
AI investigation is Outside window
Deterministic signals remain live while the bounded assessment completes.
Observed impact
- Remote command execution
- Root execution
- Server identity disclosure
- Shell spawned
- System discovery
- System information disclosure
- Workload discovery process spawned
- Workload root shell
Deterministic signals
Exploit request received non-reflected process identity output
10 observations · 10 httpRequest contains shell metacharacters and command tokens
366 observations · 12 httpResponse contains non-reflected kernel identification
5 observations · 5 httpA shell process appeared in the correlated workload and request window
307 observations · 12 processA discovery process appeared in the correlated workload and request window
22 observations · 12 process