Back to evidence

Sanitized live incident

Suspicious activity

Native source identity and targetable endpoints are private.

criticalopen
Confidence
99%
First seen
Aug 28, 2:36:06 AM PDT
Evidence through
Aug 28, 2:37:10 AM PDT
AI status
Complete
Indeterminate84% confidence

Verified process telemetry establishes two short-lived parent/child pairs of root-run dash shell executions in the same workload, approximately 63 seconds apart ([redacted], [redacted], [redacted], [redacted]). The second pair was associated with execution from inventory-resolved shared resource [redacted]. Exact lifecycle evidence shows all four processes exited quickly: the first pair nonzero and the second pair zero. This is security-relevant execution, but the bounded evidence contains no correlated HTTP event, cited network-flow event, command arguments, or actor attribution. It therefore cannot distinguish exploitation from expected image-host, automation, or administrative activity. The incident's critical suspicious-activity detector output remains intact, but malicious compromise is not established.

Attack stage
Execution observed; exploitation origin and intent undetermined
Model
gpt-5.6-sol · 10 evidence calls

Observed impact

  • Four root-run dash shell executions occurred inside the protected workload.
  • Two shell executions were associated with execution from a resource inventory-resolved as shared across workloads.
  • All four observed shell process lifecycles ended quickly; no persistence or continuing process impact is established.

Deterministic signals

Process.observed shell spawn99%

An event-driven shell execution was observed in a protected workload without correlated HTTP evidence

4 observations · 4 process
Process.correlated exit99%

A previously correlated process lifecycle exited

4 observations · 4 process
Process.shared resource activity92%

A process executed or interpreted content from an inventory-resolved resource attached to multiple workloads

2 observations · 2 process · 1 inventory

Explicit uncertainty

  • No HTTP evidence event is cited by this incident, so the originating request or non-HTTP action cannot be determined or uniquely linked to these processes.
  • No flow evidence event is cited by this incident, so the investigation cannot assess network consequences or request-to-socket causality.
  • The bounded process summaries omit command arguments and content, preventing determination of what the shells executed and whether it was malicious.
  • The common external parent PID 2212046 is observed, but its executable, owner, and operational purpose are not available in the cited evidence.
  • The source key is a workload cluster rather than a proven human or remote-actor identity.
  • Shared-resource execution does not by itself prove propagation to or impact on other workloads.
  • No evidence here proves host escape, persistence, lateral movement, command-and-control, or data theft.

Recommended actions

  1. Identify PID 2212046 and validate both execution times against expected image-host jobs, deployment hooks, health checks, and authorized administrative activity.
  2. Inspect the integrity, provenance, recent changes, mount scope, and intended executable content of shared resource [redacted]; prioritize checking all workloads to which it is attached.
  3. Preserve relevant workload, orchestrator, audit, and process telemetry around 2026-08-28T09[redacted]06Z and [redacted]10Z, including command-line and file-access records if available.
  4. If the executions are unauthorized or cannot be promptly explained, isolate the affected workload and temporarily prevent execution from the shared resource while assessing other attached workloads.
  5. Review workload privilege and reduce root execution and shared writable/executable mounts where operationally feasible.