Back to evidence

Sanitized live incident

Suspicious activity

Native source identity and targetable endpoints are private.

criticalopen
Confidence
99%
First seen
Aug 21, 4:51:47 PM PDT
Evidence through
Aug 21, 5:18:53 PM PDT
AI status
Complete
Likely true positive82% confidence

Likely true positive for suspicious privileged process activity inside the image-host workload, but not proof of an external exploit. Event-driven telemetry directly observed a root dash shell spawning a root cat process classified as targeting a sensitive file; both had exact, zero-outcome exits [redacted]. Additional root dash shells recurred from the same parent, and a later root dash execution was classified as discovery [redacted]. The available summaries do not expose command arguments, the sensitive target, authorization context, HTTP causality, or network consequences, so compromise scope and origin remain unresolved.

Attack stage
Privileged command execution and workload discovery; initial access/origin unknown
Model
gpt-5.6-sol · 9 evidence calls

Observed impact

  • Root-level shell activity occurred in the workload [redacted].
  • A root cat process classified as targeting a sensitive file executed and exited zero; actual content exposure is not established [redacted].
  • A root shell classified as discovery was spawned; its precise discovery action and result are unavailable [redacted].

Deterministic signals

Process.observed shell spawn99%

An event-driven shell execution was observed in a protected workload without correlated HTTP evidence

60 observations · 12 process
Process.observed sensitive file command99%

An event-driven process targeted a sensitive file in a protected workload without correlated HTTP evidence

2 observations · 2 process
Process.correlated exit99%

A previously correlated process lifecycle exited

61 observations · 12 process
Process.observed discovery command88%

An event-driven discovery command was observed in a protected workload without correlated HTTP evidence

1 observations · 1 process

Explicit uncertainty

  • No HTTP evidence identity is cited for these process events, so the originating request, actor, and any request-to-process causality cannot be determined.
  • No flow evidence identity is cited, so there is no basis to infer request-to-socket causality, command-and-control, lateral movement, or exfiltration.
  • The bounded summaries omit command arguments and exact file names; the sensitive target and precise discovery operation are unknown.
  • Authorization and expected workload behavior are unavailable. Repeated shells from one stable parent could reflect legitimate image-host implementation or administration, although the sensitive-target and discovery classifications warrant investigation.
  • The source key is a workload/traffic cluster and must not be treated as a unique human or remote actor identity.
  • There is no cited evidence establishing host escape, persistence, data theft, or impact outside the workload.

Recommended actions

  1. Promptly identify PID 1321728 and validate its executable, deployment provenance, owner, and whether spawning root shells is expected for the image-host role.
  2. Preserve the workload and orchestration audit trail, then review full internal process/audit logs for the omitted command arguments and exact sensitive-file target.
  3. If the parent process or commands are unauthorized, contain the workload according to policy, replace it from a trusted image, and investigate adjacent workloads using the same image or service account.
  4. Review deployment, administrative, and scheduled-job changes covering 2026-08-21T23[redacted]47Z through 2026-08-22T00[redacted]55Z to distinguish approved automation from abuse.
  5. Determine whether the sensitive target contained credentials or tokens; rotate only affected secrets if exposure is substantiated.
  6. Correlate with retained ingress, application, identity, and network telemetry using workload and process timestamps, while avoiding assumptions that temporal proximity alone proves causality.