Back to evidence

Sanitized live incident

Suspicious activity

Native source identity and targetable endpoints are private.

criticalopen
Confidence
99%
First seen
Aug 20, 1:28:10 PM PDT
Evidence through
Aug 20, 1:29:24 PM PDT
AI status
Complete
Indeterminate78% confidence

Verified event-driven process telemetry substantiates the detector’s core observations: root-run dash shells spawned, root-run id discovery occurred as a shell child, and later root-run activity mutated, accessed, and executed an inventory-resolved shared resource (process evidence [redacted], [redacted], [redacted], [redacted], [redacted]; inventory evidence [redacted]). This is materially suspicious and has potential cross-workload relevance. However, the incident cites no HTTP or flow-plane events, and the bounded process summaries do not provide command arguments, authorization context, or a malicious causality edge. Because an image-host may legitimately use root shells and shared resources, the evidence cannot currently distinguish compromise from expected automation or administration.

Attack stage
Execution and discovery with shared-resource modification/execution; origin and authorization unknown
Model
gpt-5.6-sol · 14 evidence calls

Observed impact

  • Root dash shells and root id discovery executed in the protected workload ([redacted]; [redacted]).
  • Mutation, access, and execution involved shared resource [redacted] ([redacted]; [redacted]).
  • The first observed shell exited with a zero outcome; this establishes termination only, not benign intent ([redacted]).
  • No downstream impact to other attached workloads, persistence, host escape, lateral movement, command-and-control, or data theft is established by the cited evidence.

Deterministic signals

Process.observed shell spawn99%

An event-driven shell execution was observed in a protected workload without correlated HTTP evidence

17 observations · 12 process
Process.observed discovery command88%

An event-driven discovery command was observed in a protected workload without correlated HTTP evidence

7 observations · 7 process
Process.correlated exit99%

A previously correlated process lifecycle exited

21 observations · 12 process
Process.shared resource activity92%

A process modified an inventory-resolved resource attached to multiple workloads

5 observations · 5 process · 1 inventory

Explicit uncertainty

  • The incident cites no HTTP-plane or flow-plane event IDs. Queries using process IDs were rejected as not cited on those planes, so no originating request, remote actor, network destination, or request-to-process/flow causality can be assessed.
  • The secret-free process summaries exclude exact command arguments and script contents; only executable names, classes, lineage, identity, lifecycle, and resource-operation attribution are available.
  • Authorization and deployment context are unavailable. Root shell use and shared-resource activity may be legitimate for an image-host workload, so malicious intent or compromise cannot be determined from process evidence alone.
  • The source key represents a workload/traffic cluster, not a guaranteed human or agent identity.
  • Shared-resource attachment raises cross-workload risk, but evidence does not establish that another workload consumed a malicious change or suffered a consequence.
  • Later shell lifetime and any lasting filesystem/configuration effects are not established by the decision-relevant summaries inspected.

Recommended actions

  1. Preserve the workload, process, and shared-resource telemetry for the incident window before making changes that could destroy provenance.
  2. Correlate parent PID 3075746 and the workload with orchestrator audit logs, deployment jobs, image-build tasks, operator sessions, and scheduled automation around 2026-08-20T20:28-20:29Z.
  3. Review the provenance and content changes for shared resource [redacted], and identify every workload attached to it; compare against approved artifacts and expected build outputs.
  4. If the activity is not tied to an approved job or operator, isolate or replace the affected workload, restrict the shared resource, and rotate credentials accessible to that workload according to local response procedures.
  5. Search retained telemetry for sibling processes, file modifications, authentication events, and outbound connections associated with the parent lineage; do not infer network compromise from the absence of cited flow evidence.
  6. Document expected root-shell and shared-resource behavior for the image-host role and tune only after confirming the activity is authorized and reproducible.