Back to evidence

Sanitized live incident

Confirmed compromise

Native source identity and targetable endpoints are private.

criticalconfirmed
Confidence
100%
First seen
Aug 17, 11:23:38 AM PDT
Evidence through
Aug 17, 12:40:25 PM PDT
AI status
Outside window
AI investigation is Outside window

Deterministic signals remain live while the bounded assessment completes.

Observed impact

  • New outbound destination
  • Outbound client spawned
  • Remote command execution
  • Root execution
  • Server identity disclosure
  • Shell spawned
  • System discovery
  • System information disclosure
  • Workload discovery process spawned
  • Workload root shell

Deterministic signals

Http.command injection attempt88%

Request contains shell metacharacters and command tokens

108 observations · 12 http
Process.correlated shell spawn72%

A shell process appeared in the correlated workload and request window

87 observations · 12 process
Http.server kernel output97%

Response contains non-reflected kernel identification

5 observations · 5 http
Http.server command output100%

Exploit request received non-reflected process identity output

15 observations · 12 http
Flow.correlated new outbound destination70%

The correlated workload opened a flow to a destination not previously observed in the captured baseline

1 observations · 1 flow · 1 inventory
Http.server os release output96%

Response contains non-reflected operating-system release data

3 observations · 3 http
Process.correlated discovery command72%

A discovery process appeared in the correlated workload and request window

6 observations · 6 process
Process.correlated network client72%

An outbound-capable client process appeared in the correlated workload and request window

3 observations · 3 process