Live public case
Suspicious activity
Last activity Aug 18, 12:28:52 PM PDT
Evidence-grounded assessment
Likely same operation
The two preserved incident threads are best treated as a likely single operational sequence, not a proven one. Both record closely spaced, root-context shell/discovery behavior in the same protected workload, and deterministic link [redacted] associates incidents [redacted] and [redacted] with 0.93 confidence. Incident [redacted] contains initial dash/id sequences at 18:22, while incident [redacted] begins about 25 minutes later with recurring dash/discovery activity, including env discovery and sensitive-file targeting. This behavioral continuity supports likely continuation, but the same-workload link does not establish one actor or causal chain; neither incident supplies correlated HTTP or flow evidence identifying the initiating action.
Shared case lifecycle
Resolved · Authorized test
This read-only state comes from the same canonical workflow as the private operator console. Notes and append-only action history remain private.
Observed impact
- Correlated process exited
- Outbound client spawned
- Sensitive file access command observed
- Shell spawned
- Workload discovery process spawned
- Workload root shell
- Root-context shell and identity-discovery processes executed inside the protected workload.
- All six observed shell/discovery processes exited; four had zero outcomes and two had nonzero outcomes.
- No observed network connection, persistence, host escape, lateral movement, command-and-control, or data theft is established by the cited evidence.
- Root-context shell and discovery processes executed within the protected workload.
- A root-context shell process targeted a sensitive resource; access success or content disclosure is not proven.
- At least one observed shell/discovery lifecycle exited successfully, but that does not establish the result of every command.
Recommended actions
- Review workload orchestration, job, administrative-session, and audit records spanning 18:15–19:35 UTC to determine whether the activity in [redacted] and [redacted] had a common authorized initiator.
- Preserve and compare complete process ancestry and available command/path telemetry for [redacted] and [redacted], especially around the 25-minute gap and sensitive-file classification.
- If available through normal investigative controls, correlate workload access, identity, HTTP, and network-flow logs with both incidents before attributing an actor, exploit path, or outbound consequence.
- Maintain the two incident boundaries while tracking the likely relationship represented by link [redacted].
Attack timeline
2 incident threads
Resolution changes operator work, not the preserved attack evidence below.
- 1Suspicious activityopen
Verified process telemetry establishes three root-context dash shell executions, each followed by a root-context id discovery process in the same workload (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). Exact lifecycle evidence shows all six processes exited; the first pair had nonzero outcomes and the later four had zero outcomes (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). This supports execution and discovery inside the workload, but not a malicious origin: the incident cites no HTTP or flow events, and the available summaries omit command arguments and authorization context. The detector's critical suspicious-activity output remains intact, while the available evidence is insufficient to distinguish exploitation from legitimate administrative or workload behavior.
- 2Suspicious activityopen
Direct event-driven process telemetry supports real suspicious activity inside the workload: a root-run dash process classified as both shell and discovery spawned a root-run env child [redacted], similar root shell/discovery executions recurred later [redacted], and a root-run dash process classified as a shell and sensitive-file tool targeted a sensitive resource [redacted]. This makes the behavioral detection likely valid, but available evidence does not identify the initiating actor or distinguish malicious execution from authorized administrative/lab automation. No HTTP or flow evidence references were available to establish an ingress vector or network consequence.