Back to evidence

Sanitized live incident

Suspicious activity

Native source identity and targetable endpoints are private.

criticalopen
Confidence
99%
First seen
Aug 23, 2:00:46 PM PDT
Evidence through
Aug 23, 2:16:03 PM PDT
AI status
Complete
Indeterminate91% confidence

The incident is behaviorally substantiated but maliciousness is not established. Event-driven telemetry shows repeated root-run dash shell executions in the processor workload, including execution/access/mutation classifications involving shared resource [redacted]. A later root-run uname discovery process adds suspicion [redacted]. Exact lifecycle evidence shows sampled shells exited, with both zero and nonzero outcomes; this proves process termination but not benign intent or request causality [redacted]. No cited HTTP or flow events were available through the bounded evidence tools, and process summaries exclude arguments, so the originating action, actor, exact commands, authorization, and network consequences remain unresolved. These could represent compromise or expected processor/administrative automation.

Attack stage
Execution and discovery; origin and authorization undetermined
Model
gpt-5.6-sol · 12 evidence calls

Observed impact

  • Root-run dash shell processes executed inside the protected processor workload [redacted].
  • Process telemetry classified operations on shared resource [redacted] as execution, access, and mutation [process:[redacted], process:[redacted], process:a0e817038fbadce8ed04

Deterministic signals

Process.observed shell spawn99%

An event-driven shell execution was observed in a protected workload without correlated HTTP evidence

26 observations · 12 process
Process.shared resource activity92%

A process executed or interpreted content from an inventory-resolved resource attached to multiple workloads

8 observations · 8 process · 2 inventory
Process.correlated exit99%

A previously correlated process lifecycle exited

29 observations · 12 process
Process.observed discovery command88%

An event-driven discovery command was observed in a protected workload without correlated HTTP evidence

1 observations · 1 process

Explicit uncertainty

  • No HTTP evidence IDs are cited for this incident; the bounded HTTP query could not establish an originating request or request-to-process causality.
  • No flow evidence IDs are cited for this incident; outbound network behavior, destination novelty, and request-to-socket causality cannot be assessed.
  • The bounded process summaries omit arguments and content, so the exact shell commands, accessed data, and resource changes are unknown.
  • The process evidence does not establish whether the activity was authorized processor logic, administrative automation, or malicious execution.
  • The source key is a workload cluster rather than a proven human or remote actor identity.
  • No evidence proves host escape, persistence, lateral movement, command-and-control, or data theft.

Recommended actions

  1. Validate parent process PID 1322209 and the processor workload's expected job or plugin behavior against deployment configuration, scheduler/queue records, and change tickets for 2026-08-23T21[redacted]46Z–[redacted]03Z.
  2. Preserve the workload's process telemetry, orchestrator audit history, application/job logs, and shared-resource audit history before routine rotation.
  3. Review integrity and authorized changes for shared resource [redacted], and assess every workload attached to it for unexpected execution or modification.
  4. Correlate the shell and uname events with control-plane exec sessions, cron/scheduler activity, image entrypoints, and service-account actions to identify the originating actor or automation.
  5. Review network telemetry for the affected workload over the incident window because no cited flow evidence was available here.
  6. If the executions or resource mutations are not expected, isolate the workload, restrict shared-resource write access, rotate exposed workload credentials, and redeploy from a known-good image; otherwise document the expected behavior and tune the detector narrowly.