Back to cases

Live public case

Suspicious activity

Last activity Aug 18, 12:28:52 PM PDT

criticalCompleteResolved · Authorized test

Evidence-grounded assessment

Likely same operation

The two preserved incident threads are best treated as a likely single operational sequence, not a proven one. Both record closely spaced, root-context shell/discovery behavior in the same protected workload, and deterministic link [redacted] associates incidents [redacted] and [redacted] with 0.93 confidence. Incident [redacted] contains initial dash/id sequences at 18:22, while incident [redacted] begins about 25 minutes later with recurring dash/discovery activity, including env discovery and sensitive-file targeting. This behavioral continuity supports likely continuation, but the same-workload link does not establish one actor or causal chain; neither incident supplies correlated HTTP or flow evidence identifying the initiating action.

Shared case lifecycle

Resolved · Authorized test

This read-only state comes from the same canonical workflow as the private operator console. Notes and append-only action history remain private.

Observed impact

  • Correlated process exited
  • Outbound client spawned
  • Sensitive file access command observed
  • Shell spawned
  • Workload discovery process spawned
  • Workload root shell
  • Root-context shell and identity-discovery processes executed inside the protected workload.
  • All six observed shell/discovery processes exited; four had zero outcomes and two had nonzero outcomes.
  • No observed network connection, persistence, host escape, lateral movement, command-and-control, or data theft is established by the cited evidence.
  • Root-context shell and discovery processes executed within the protected workload.
  • A root-context shell process targeted a sensitive resource; access success or content disclosure is not proven.
  • At least one observed shell/discovery lifecycle exited successfully, but that does not establish the result of every command.

Recommended actions

  1. Review workload orchestration, job, administrative-session, and audit records spanning 18:15–19:35 UTC to determine whether the activity in [redacted] and [redacted] had a common authorized initiator.
  2. Preserve and compare complete process ancestry and available command/path telemetry for [redacted] and [redacted], especially around the 25-minute gap and sensitive-file classification.
  3. If available through normal investigative controls, correlate workload access, identity, HTTP, and network-flow logs with both incidents before attributing an actor, exploit path, or outbound consequence.
  4. Maintain the two incident boundaries while tracking the likely relationship represented by link [redacted].

Attack timeline

2 incident threads

Resolution changes operator work, not the preserved attack evidence below.

  1. 1
    Suspicious activityopen

    Verified process telemetry establishes three root-context dash shell executions, each followed by a root-context id discovery process in the same workload (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). Exact lifecycle evidence shows all six processes exited; the first pair had nonzero outcomes and the later four had zero outcomes (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). This supports execution and discovery inside the workload, but not a malicious origin: the incident cites no HTTP or flow events, and the available summaries omit command arguments and authorization context. The detector's critical suspicious-activity output remains intact, while the available evidence is insufficient to distinguish exploitation from legitimate administrative or workload behavior.

  2. 2
    Suspicious activityopen

    Direct event-driven process telemetry supports real suspicious activity inside the workload: a root-run dash process classified as both shell and discovery spawned a root-run env child [redacted], similar root shell/discovery executions recurred later [redacted], and a root-run dash process classified as a shell and sensitive-file tool targeted a sensitive resource [redacted]. This makes the behavioral detection likely valid, but available evidence does not identify the initiating actor or distinguish malicious execution from authorized administrative/lab automation. No HTTP or flow evidence references were available to establish an ingress vector or network consequence.