Back to cases

Live public case

Suspicious activity

Last activity Aug 19, 12:27:45 PM PDT

criticalNot required

Evidence-grounded assessment

Not required

Verified event-driven process telemetry shows repeated root-run dash shells in the protected workload, including child discovery utilities and a root-run cat process classified as targeting a sensitive file. This strongly supports unauthorized or attack-like command execution with discovery and sensitive-file access activity. However, no HTTP or flow evidence references are available to establish the initiating action, actor, exploit vector, request-to-process causality, network consequence, or whether the activity was authorized administration or lab automation.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Correlated process exited
  • Sensitive file access command observed
  • Shell spawned
  • Workload discovery process spawned
  • Workload root shell
  • Root-level shell and discovery processes executed inside the workload.
  • A root-level cat process classified as targeting a sensitive file executed; actual file contents obtained or disclosed are not established.
  • Observed command processes exited, including verified zero-outcome lifecycles for sampled shell/child chains.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Suspicious activityopen

      Verified event-driven process telemetry shows repeated root-run dash shells in the protected workload, including child discovery utilities and a root-run cat process classified as targeting a sensitive file. This strongly supports unauthorized or attack-like command execution with discovery and sensitive-file access activity. However, no HTTP or flow evidence references are available to establish the initiating action, actor, exploit vector, request-to-process causality, network consequence, or whether the activity was authorized administration or lab automation.