Back to cases

Live public case

Suspicious activity

Last activity Aug 19, 9:41:16 AM PDT

criticalNot required

Evidence-grounded assessment

Not required

Likely true positive for suspicious in-workload execution, but not proof of a remote exploit. Event-driven telemetry shows repeated root-run dash executions, including discovery-classified activity, plus a root-run cat child targeting a sensitive file [redacted]. Exact lifecycle evidence shows the sensitive-targeting shell and cat exited nonzero, while other discovery/shell instances exited zero [redacted]. No cited HTTP or flow events were available to establish origin, request causality, actor identity, egress, or exploitation.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Correlated process exited
  • Sensitive file access command observed
  • Shell spawned
  • Workload discovery process spawned
  • Workload root shell
  • Root-run shell processes executed inside the workload [redacted].
  • Discovery-classified root shell activity occurred [redacted].
  • A root-run cat child targeted a sensitive file; its exact lifecycle exited nonzero, so successful disclosure is not established [redacted].

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Suspicious activityopen

      Likely true positive for suspicious in-workload execution, but not proof of a remote exploit. Event-driven telemetry shows repeated root-run dash executions, including discovery-classified activity, plus a root-run cat child targeting a sensitive file [redacted]. Exact lifecycle evidence shows the sensitive-targeting shell and cat exited nonzero, while other discovery/shell instances exited zero [redacted]. No cited HTTP or flow events were available to establish origin, request causality, actor identity, egress, or exploitation.