Back to evidence

Sanitized live incident

Suspicious activity

Native source identity and targetable endpoints are private.

criticalopen
Confidence
99%
First seen
Aug 21, 2:13:25 PM PDT
Evidence through
Aug 21, 2:13:25 PM PDT
AI status
Complete
Indeterminate90% confidence

Two event-driven process records prove that separate dash shell processes executed as root in the same protected workload within about 177 ms (process evidence [redacted] and [redacted]). This validates the detector's observed shell-spawn consequence, but the available summaries do not expose commands, parent identities, initiating action, or a causal HTTP/flow chain. Root dash execution can represent either malicious command execution or legitimate workload/administrative automation, so exploitation or compromise cannot be adjudicated from the cited evidence.

Attack stage
Execution observed; malicious origin and causality indeterminate
Model
gpt-5.6-sol · 5 evidence calls

Observed impact

  • Two root-context dash shell processes executed in the protected workload (process evidence [redacted] and [redacted]).
  • No further security consequence is established by the available cited evidence.

Deterministic signals

Process.observed shell spawn99%

An event-driven shell execution was observed in a protected workload without correlated HTTP evidence

2 observations · 2 process

Explicit uncertainty

  • No cited HTTP evidence was available to identify an initiating request or establish request-to-process causality.
  • No cited flow evidence was available to assess network activity associated with the shell executions.
  • The bounded process summaries do not provide command arguments, parent executable identities, process ancestry details beyond observed PPIDs, or operator identity.
  • No process-exit lifecycle evidence was cited, so duration and exit outcome are unknown.
  • The source key is a workload cluster and does not identify a human or remote actor.
  • Whether these root shells were expected image-host automation, authorized administration, or malicious execution remains unresolved.

Recommended actions

  1. Validate both PID/PPID chains against the workload's expected image-host processes, deployment activity, scheduled jobs, and authorized administrative actions at the observed time.
  2. Review retained workload and orchestrator logs for the initiating action and full command context while preserving the cited process records and integrity hashes.
  3. Inspect temporally adjacent HTTP and network telemetry, if retained, for independently attributable activity; do not infer causality from timing alone.
  4. If the executions are not expected, isolate the workload according to established response procedures, rotate exposed workload credentials, and rebuild from a trusted image.
  5. Reduce routine root execution and shell availability in the workload where operationally feasible, and alert on future shell launches with command and ancestry context.