Sanitized live incident
Suspicious activity
Native source identity and targetable endpoints are private.
- Confidence
- 99%
- First seen
- Aug 23, 7:15:09 PM PDT
- Evidence through
- Aug 23, 7:44:59 PM PDT
- AI status
- Complete
Likely unauthorized execution and discovery inside the protected processor workload. Event-driven telemetry directly observed multiple dash shell executions as root, including activity recurring from 02:15 through at least 02:40 (process evidence [redacted], [redacted], and [redacted]). A root dash process also spawned root id and uname discovery processes ([redacted], [redacted], and [redacted]). This pattern is suspicious enough for a likely true positive, but process summaries omit arguments and do not establish whether the activity was authorized or how it originated. No HTTP or flow references are available in the incident, so exploitation, request causality, and network consequences remain unproven.
- Attack stage
- Workload execution and system discovery
- Model
- gpt-5.6-sol · 13 evidence calls
Observed impact
- Root-level shell processes executed inside the protected processor workload.
- Root-level identity and system-information discovery processes executed inside the workload.
- At least the first observed shell and its id child exited successfully; no persistence or network impact is established.
Deterministic signals
An event-driven shell execution was observed in a protected workload without correlated HTTP evidence
17 observations · 12 processAn event-driven discovery command was observed in a protected workload without correlated HTTP evidence
6 observations · 6 processA previously correlated process lifecycle exited
20 observations · 12 processExplicit uncertainty
- The process summaries do not expose command arguments, parent executable identity, initiating actor, or authorization context; legitimate processor or administrative behavior cannot be excluded.
- The incident contains no cited HTTP evidence. HTTP evidence lookup cannot accept the process IDs as HTTP references, so no request can be linked to these executions and exploit origin is unknown.
- The incident contains no cited flow evidence. Flow evidence lookup cannot accept the process IDs as flow references, so outbound connectivity and request-to-socket causality cannot be assessed.
- The source key is a workload cluster, not a proven human or remote-actor identity.
- No cited evidence proves host escape, persistence, lateral movement, command-and-control, or data theft.
Recommended actions
- Promptly validate the shell and discovery activity against the processor workload's expected behavior, deployment history, scheduled jobs, and authorized administrative activity.
- If the activity is not immediately explained, contain or replace the affected workload using the organization's approved response procedure while preserving process and application telemetry.
- Review the parent process corresponding to the observed lineage and retrieve application/job audit records around 02:15–02:45 UTC to identify the initiating task or input.
- Harden the workload by running it as a non-root identity where feasible and restricting shell/tool availability and process-spawn capability to operational requirements.
- Review credentials and secrets accessible to the workload; rotate them if unauthorized execution is confirmed or credential exposure cannot be excluded.