Back to evidence

Sanitized live incident

Suspicious activity

Native source identity and targetable endpoints are private.

criticalopen
Confidence
99%
First seen
Aug 30, 6:38:11 PM PDT
Evidence through
Aug 30, 6:38:50 PM PDT
AI status
Complete
Likely true positive80% confidence

Likely true positive for suspicious in-workload command execution, but not proof of remote exploitation or compromise. Event-driven process telemetry shows repeated root-run dash shells in one workload, including discovery activity and a root-run cat process classified as targeting a sensitive file (process evidence [redacted], [redacted], [redacted], [redacted], [redacted], and [redacted]). The first and latest cited shells exited successfully, indicating short-lived execution rather than persistence ([redacted] and [redacted]). No HTTP or flow evidence reference is available in this incident, so the trigger, actor, authorization, and any network consequence remain unknown.

Attack stage
Execution and discovery; possible sensitive-file access
Model
gpt-5.6-sol · 8 evidence calls

Observed impact

  • Root-run shell processes executed inside the protected workload ([redacted]; [redacted]).
  • A root-run cat process classified as a sensitive-file tool with a sensitive target was spawned as a child of a shell ([redacted]; [redacted]).
  • Observed cited shell lifecycles were short-lived and exited zero; no persistence is established ([redacted]; [redacted]).

Deterministic signals

Process.observed shell spawn99%

An event-driven shell execution was observed in a protected workload without correlated HTTP evidence

9 observations · 9 process
Process.correlated exit99%

A previously correlated process lifecycle exited

11 observations · 11 process
Process.observed discovery command88%

An event-driven discovery command was observed in a protected workload without correlated HTTP evidence

3 observations · 3 process
Process.observed sensitive file command99%

An event-driven process targeted a sensitive file in a protected workload without correlated HTTP evidence

2 observations · 2 process

Explicit uncertainty

  • No HTTP evidence reference is cited by this incident; attempts to query HTTP evidence with process IDs were rejected. The originating request or action and any request-to-process causality are unknown.
  • No flow evidence reference is cited by this incident; attempts to query flow evidence with process IDs were rejected. Network activity, destination novelty, command-and-control, and exfiltration are not established.
  • Process summaries omit exact command arguments and the sensitive path, so the purpose of the shells and the specific targeted file cannot be determined.
  • The source key denotes a workload cluster, not a human or remote actor identity.
  • The evidence does not determine whether this activity was authorized workload behavior, administration, testing, or malicious execution.
  • No evidence establishes host escape, persistence, lateral movement, command-and-control, or data theft.

Recommended actions

  1. Immediately validate the activity with the workload owner by correlating parent PID 2212455, deployment/job history, administrative audit records, and application logs for 2026-08-31 [redacted]11Z–[redacted]51Z.
  2. If the sequence is not expected, contain or replace the affected workload using established procedures and preserve process, orchestration, and application telemetry before cleanup.
  3. Determine which sensitive file was targeted and whether access succeeded. Rotate affected credentials or secrets if exposure is confirmed or cannot be safely excluded.
  4. Review why the processor workload executes as root; where feasible, run it as a non-root identity and restrict shell/tool availability and filesystem access.
  5. Add approved-job or parent-lineage baselining only after confirming legitimate behavior; do not suppress the alert solely because the processes exited quickly.