Akamai ExAR detected and investigated a multistage intrusion affecting supply chain infrastructure in LATAM. By correlating workload, process, network, and threat intelligence signals, ExAR helped the customer contain the incident before it developed into a broader operational security event.
Our investigation identified suspicious activity across Linux and OpenShift workloads, Windows systems in the DMZ, and network services. Observed behaviors included outbound C2 traffic, Active Directory enumeration, a separate socat listener, and inbound connections from malicious external infrastructure.
ExAR connected these signals within the context of the customer's segmentation policies. This context helped analysts assess which communications were expected, which paths were permitted, and where the activity deviated from the intended network design.
Within ExAR, our AI threat investigator accelerated initial correlation and reporting. Human analysts then expanded the investigation, examined the affected web server, identified evidence supporting the likely initial access vector, and enriched the C2 infrastructure with threat intelligence.
This incident illustrates how microsegmentation combined with threat intelligence can constrain attack paths when appropriate policies are enforced. Guardicore deception technology was not deployed in this environment, but it could provide an additional high-fidelity detection layer if an attacker interacted with a decoy or lure.