Live public case
Suspicious activity
Last activity Aug 18, 12:28:15 PM PDT
Evidence-grounded assessment
Not required
Likely true positive for suspicious root-level command execution inside the workload, but not proof of external exploitation. Event-driven process evidence shows a root dash shell spawning discovery command id [redacted], later followed by a root dash/head chain classified as targeting a sensitive file [redacted]. Additional root dash executions continued through [redacted]36Z [redacted]. The repeated shell, discovery, and sensitive-file pattern strongly supports genuine suspicious activity. However, no HTTP or flow references are available to identify an initiating request or network consequence, and authorization or lab activity cannot be excluded.
Shared case lifecycle
Resolved · Authorized test
This read-only state comes from the same canonical workflow as the private operator console. Notes and append-only action history remain private.
Observed impact
- Correlated process exited
- Sensitive file access command observed
- Shell spawned
- Workload discovery process spawned
- Workload root shell
- Root-context shell and discovery processes executed inside the protected workload.
- A root-context shell spawned a sensitive-file tool, showing sensitive-file targeting; content disclosure is not established.
- Repeated shell activity continued for several minutes, increasing concern beyond a single incidental process.
Recommended actions
Attack timeline
1 incident threads
Resolution changes operator work, not the preserved attack evidence below.
- 1Suspicious activityopen
Likely true positive for suspicious root-level command execution inside the workload, but not proof of external exploitation. Event-driven process evidence shows a root dash shell spawning discovery command id [redacted], later followed by a root dash/head chain classified as targeting a sensitive file [redacted]. Additional root dash executions continued through [redacted]36Z [redacted]. The repeated shell, discovery, and sensitive-file pattern strongly supports genuine suspicious activity. However, no HTTP or flow references are available to identify an initiating request or network consequence, and authorization or lab activity cannot be excluded.