Back to cases

Live public case

Observed workload execution

Last activity Aug 18, 11:22:44 AM PDT

criticalNot requiredReopened by new evidence

Evidence-grounded assessment

Not required

Verified process telemetry establishes three root-context dash shell executions, each followed by a root-context id discovery process in the same workload (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). Exact lifecycle evidence shows all six processes exited; the first pair had nonzero outcomes and the later four had zero outcomes (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). This supports execution and discovery inside the workload, but not a malicious origin: the incident cites no HTTP or flow events, and the available summaries omit command arguments and authorization context. The detector's critical suspicious-activity output remains intact, while the available evidence is insufficient to distinguish exploitation from legitimate administrative or workload behavior.

Shared case lifecycle

Reopened by new evidence

This read-only state comes from the same canonical workflow as the private operator console. Notes and append-only action history remain private.

Observed impact

  • Correlated process exited
  • Outbound client spawned
  • Shell spawned
  • Workload discovery process spawned
  • Workload root shell
  • Root-context shell and identity-discovery processes executed inside the protected workload.
  • All six observed shell/discovery processes exited; four had zero outcomes and two had nonzero outcomes.
  • No observed network connection, persistence, host escape, lateral movement, command-and-control, or data theft is established by the cited evidence.

Recommended actions

    Attack timeline

    1 incident threads

    Resolution changes operator work, not the preserved attack evidence below.

    1. 1
      Suspicious activityopen

      Verified process telemetry establishes three root-context dash shell executions, each followed by a root-context id discovery process in the same workload (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). Exact lifecycle evidence shows all six processes exited; the first pair had nonzero outcomes and the later four had zero outcomes (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). This supports execution and discovery inside the workload, but not a malicious origin: the incident cites no HTTP or flow events, and the available summaries omit command arguments and authorization context. The detector's critical suspicious-activity output remains intact, while the available evidence is insufficient to distinguish exploitation from legitimate administrative or workload behavior.