Live public case
Suspicious activity
Last activity Aug 19, 9:41:16 AM PDT
Evidence-grounded assessment
Not required
Likely true positive for suspicious in-workload execution, but not proof of a remote exploit. Event-driven telemetry shows repeated root-run dash executions, including discovery-classified activity, plus a root-run cat child targeting a sensitive file [redacted]. Exact lifecycle evidence shows the sensitive-targeting shell and cat exited nonzero, while other discovery/shell instances exited zero [redacted]. No cited HTTP or flow events were available to establish origin, request causality, actor identity, egress, or exploitation.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Correlated process exited
- Sensitive file access command observed
- Shell spawned
- Workload discovery process spawned
- Workload root shell
- Root-run shell processes executed inside the workload [redacted].
- Discovery-classified root shell activity occurred [redacted].
- A root-run cat child targeted a sensitive file; its exact lifecycle exited nonzero, so successful disclosure is not established [redacted].
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Suspicious activityopen
Likely true positive for suspicious in-workload execution, but not proof of a remote exploit. Event-driven telemetry shows repeated root-run dash executions, including discovery-classified activity, plus a root-run cat child targeting a sensitive file [redacted]. Exact lifecycle evidence shows the sensitive-targeting shell and cat exited nonzero, while other discovery/shell instances exited zero [redacted]. No cited HTTP or flow events were available to establish origin, request causality, actor identity, egress, or exploitation.