Back to evidence

Sanitized live incident

Suspicious activity

Native source identity and targetable endpoints are private.

criticalopen
Confidence
99%
First seen
Aug 19, 9:40:31 AM PDT
Evidence through
Aug 19, 9:41:16 AM PDT
AI status
Complete
Likely true positive81% confidence

Likely true positive for suspicious in-workload execution, but not proof of a remote exploit. Event-driven telemetry shows repeated root-run dash executions, including discovery-classified activity, plus a root-run cat child targeting a sensitive file [redacted]. Exact lifecycle evidence shows the sensitive-targeting shell and cat exited nonzero, while other discovery/shell instances exited zero [redacted]. No cited HTTP or flow events were available to establish origin, request causality, actor identity, egress, or exploitation.

Attack stage
Execution, discovery, and sensitive-file access attempt [redacted]
Model
gpt-5.6-sol · 11 evidence calls

Observed impact

  • Root-run shell processes executed inside the workload [redacted].
  • Discovery-classified root shell activity occurred [redacted].
  • A root-run cat child targeted a sensitive file; its exact lifecycle exited nonzero, so successful disclosure is not established [redacted].

Deterministic signals

Process.observed shell spawn99%

An event-driven shell execution was observed in a protected workload without correlated HTTP evidence

10 observations · 10 process
Process.correlated exit99%

A previously correlated process lifecycle exited

11 observations · 11 process
Process.observed discovery command88%

An event-driven discovery command was observed in a protected workload without correlated HTTP evidence

2 observations · 2 process
Process.observed sensitive file command99%

An event-driven process targeted a sensitive file in a protected workload without correlated HTTP evidence

2 observations · 2 process

Explicit uncertainty

  • No HTTP evidence reference was cited for these process events; an HTTP-plane lookup using the process IDs was rejected, so the originating request or non-HTTP action and any request-to-process causality remain unknown.
  • No flow evidence reference was cited for these process events; a flow-plane lookup using the process IDs was rejected, so egress, destination novelty, and request-to-socket causality cannot be assessed.
  • The workload source key is a traffic/workload cluster, not a verified human or remote actor identity.
  • The bounded summaries omit exact command arguments and sensitive-file identity, preventing determination of intent and of what object was targeted.
  • Root shell and discovery activity may be authorized administration, automation, or attack-lab behavior; authorization context was not available.
  • Process execution and exit outcomes do not prove persistence, host escape, lateral movement, command-and-control, or data theft.

Recommended actions

  1. Immediately validate the activity with the workload owner and compare the timestamps and parent process lineage against approved jobs, health checks, deployment hooks, and attack-lab exercises.
  2. Investigate the common parent process represented by PPID 3075746 in the cited summaries and preserve its surrounding process tree, workload audit logs, and orchestration events.
  3. Review file-access audit telemetry for the sensitive target around [redacted]34Z; the cat process exited nonzero, but process telemetry alone cannot determine whether any content was read before exit.
  4. Scope the workload for additional unexpected children, file changes, credential access, and network activity before and after the observed interval.
  5. If the activity is unauthorized, contain or replace the workload, preserve forensic artifacts, and rotate only credentials shown by further evidence to have been exposed.
  6. Add or verify HTTP and conntrack correlation coverage for this workload so future executions can be attributed without inferring causality from timing alone.