Live public case
Observed workload execution
Last activity Sep 1, 6:42:09 PM PDT
Evidence-grounded assessment
Not required
The detector's critical suspicious-activity output is supported at the consequence level: event-driven telemetry observed a root-context dash shell in the processor workload and a root-context child id discovery process, followed by zero-result exits. However, the available evidence does not establish whether this execution was malicious, authorized workload behavior, or administrative/testing activity. No incident-cited HTTP or flow evidence was available to establish an originating request, actor, request-to-process causal edge, or network consequence. Therefore, execution and discovery are confirmed, while exploitation or compromise remains indeterminate.
- Protected workloads
- Protected workload A
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Correlated process exited
- Shell spawned
- Workload discovery process spawned
- Workload root shell
- A root-context shell and a child identity-discovery utility executed inside the processor workload.
- The sampled shell and discovery process exited successfully; this confirms completed execution, not malicious purpose.
- No supported impact beyond in-workload command execution and discovery can be established from the cited evidence.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Suspicious activityopen
The detector's critical suspicious-activity output is supported at the consequence level: event-driven telemetry observed a root-context dash shell in the processor workload and a root-context child id discovery process, followed by zero-result exits. However, the available evidence does not establish whether this execution was malicious, authorized workload behavior, or administrative/testing activity. No incident-cited HTTP or flow evidence was available to establish an originating request, actor, request-to-process causal edge, or network consequence. Therefore, execution and discovery are confirmed, while exploitation or compromise remains indeterminate.