Back to evidence

Sanitized live incident

Suspicious activity

Native source identity and targetable endpoints are private.

criticalopen
Confidence
99%
First seen
Aug 28, 2:36:06 AM PDT
Evidence through
Aug 28, 2:37:10 AM PDT
AI status
Complete
Indeterminate91% confidence

The underlying process activity is verified: two event-driven root dash executions from the same parent occurred about 63 seconds apart in the same workload, each followed by a root env-classified discovery child [redacted]. The second chain recorded mutation/access against inventory-resolved shared resource [redacted]. However, no cited HTTP or flow evidence is available, process summaries expose no arguments, and the stable parent plus repeated pattern can fit either unauthorized execution or a legitimate recurring workload task. Therefore the observed execution and resource activity are real, but malicious exploitation or compromise cannot be adjudicated from the available evidence.

Attack stage
Execution and discovery with shared-resource activity; origin and intent undetermined
Model
gpt-5.6-sol · 9 evidence calls

Observed impact

  • Two root shell executions and root discovery-process executions occurred in the workload [redacted].
  • The second process chain recorded mutation and access involving shared resource [redacted], which inventory attributed as shared across workloads [[redacted], [redacted], 668
  • Observed shell/discovery lifecycles ended: the first shell had a nonzero outcome, while the second shell and its child had zero outcomes [redacted].

Deterministic signals

Process.observed shell spawn99%

An event-driven shell execution was observed in a protected workload without correlated HTTP evidence

2 observations · 2 process
Process.observed discovery command88%

An event-driven discovery command was observed in a protected workload without correlated HTTP evidence

2 observations · 2 process
Process.correlated exit99%

A previously correlated process lifecycle exited

3 observations · 3 process
Process.shared resource activity92%

A process modified an inventory-resolved resource attached to multiple workloads

3 observations · 3 process · 1 inventory

Explicit uncertainty

  • No HTTP evidence reference is cited by this incident, so the originating request or actor cannot be established; the source key is a workload cluster rather than a guaranteed identity.
  • No flow evidence reference is cited by this incident, so outbound communication, request-to-socket causality, and network consequences cannot be assessed.
  • The bounded process summaries omit command arguments and resource contents, preventing determination of the commands' purpose or what data was changed or accessed.
  • The stable parent PID and approximately 63-second repetition may indicate a recurring legitimate task, but available evidence does not identify the parent executable, scheduler, deployment intent, or authorization.
  • Process exit outcomes establish termination only; they do not establish whether the resource mutation achieved an intended effect or whether an HTTP request caused any process.
  • There is no cited evidence proving persistence, host escape, lateral movement, command-and-control, credential theft, or data exfiltration.

Recommended actions

  1. Identify PPID 2212455 from retained workload/deployment telemetry and compare the two shell chains with approved processor startup hooks, scheduled jobs, health checks, and administrative activity.
  2. Review authorized scripts and deployment changes around 09:36–09:37Z to determine whether root dash-to-env execution and the roughly one-minute recurrence are expected.
  3. Inspect resource [redacted] for unauthorized changes and assess every workload attached to it; restore from a known-good version if the mutation was not approved.
  4. Preserve relevant process, workload, orchestration, and audit telemetry. If the parent or resource change is unauthorized, isolate the affected workload and rotate any credentials materially exposed through the shared resource.
  5. Add or verify least-privilege controls so the processor does not run as root or mutate cross-workload resources unless operationally required.