Primary Hypothesis
Coordinated web compromise with credential pressure.
The agent initially treated brute force as isolated. After correlation, it promoted the case because web, DNS, and EDR events formed a consistent attacker timeline.
Evidence Timeline
AUTH-00100:10:11ZSSH failed password for app-adminAUTH-00600:11:02ZSSH success from same source ASNWEB-00200:13:44ZPHP upload to public web rootEDR-00100:14:05Zphp-fpm starts /bin/shDNS-00100:14:08ZNewly observed beacon domain queriedContain
Isolate web-01 and block outbound beaconing.
Isolate web-01 and block outbound beaconing.
Preserve
Capture auth logs, web root, process telemetry, and hashes.
Capture auth logs, web root, process telemetry, and hashes.
Recover
Rotate app-admin credentials and invalidate sessions.
Rotate app-admin credentials and invalidate sessions.
Hunt
Search adjacent hosts for the same domain and PHP process pattern.
Search adjacent hosts for the same domain and PHP process pattern.