Live public case
Observed workload execution
Last activity Aug 18, 11:22:44 AM PDT
Evidence-grounded assessment
Not required
Verified process telemetry establishes three root-context dash shell executions, each followed by a root-context id discovery process in the same workload (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). Exact lifecycle evidence shows all six processes exited; the first pair had nonzero outcomes and the later four had zero outcomes (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). This supports execution and discovery inside the workload, but not a malicious origin: the incident cites no HTTP or flow events, and the available summaries omit command arguments and authorization context. The detector's critical suspicious-activity output remains intact, while the available evidence is insufficient to distinguish exploitation from legitimate administrative or workload behavior.
Shared case lifecycle
Reopened by new evidence
This read-only state comes from the same canonical workflow as the private operator console. Notes and append-only action history remain private.
Observed impact
- Correlated process exited
- Outbound client spawned
- Shell spawned
- Workload discovery process spawned
- Workload root shell
- Root-context shell and identity-discovery processes executed inside the protected workload.
- All six observed shell/discovery processes exited; four had zero outcomes and two had nonzero outcomes.
- No observed network connection, persistence, host escape, lateral movement, command-and-control, or data theft is established by the cited evidence.
Recommended actions
Attack timeline
1 incident threads
Resolution changes operator work, not the preserved attack evidence below.
- 1Suspicious activityopen
Verified process telemetry establishes three root-context dash shell executions, each followed by a root-context id discovery process in the same workload (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). Exact lifecycle evidence shows all six processes exited; the first pair had nonzero outcomes and the later four had zero outcomes (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). This supports execution and discovery inside the workload, but not a malicious origin: the incident cites no HTTP or flow events, and the available summaries omit command arguments and authorization context. The detector's critical suspicious-activity output remains intact, while the available evidence is insufficient to distinguish exploitation from legitimate administrative or workload behavior.