Sanitized live incident
Suspicious activity
Native source identity and targetable endpoints are private.
- Confidence
- 99%
- First seen
- Aug 28, 3:31:17 PM PDT
- Evidence through
- Aug 28, 3:57:47 PM PDT
- AI status
- Complete
Likely true positive for suspicious workload-level execution, but not a proven externally initiated exploit. Event-driven telemetry directly observed repeated root-run dash shells, discovery activity, a sensitive-file-targeting shell, and execution from an inventory-resolved shared resource in the same workload context [redacted]. The repeated common parent PID may indicate an application service or administrative automation rather than a remote actor, and no HTTP or flow evidence was available to establish origin, request-to-process causality, or network consequences. At least one observed shell had an exact exit event with a zero outcome; that establishes process completion only, not benign intent or exploit causality [redacted].
- Attack stage
- Workload execution and discovery with sensitive-file targeting and shared-resource execution
- Model
- gpt-5.6-sol · 14 evidence calls
Observed impact
- A root-run dash shell executed inside the protected workload [redacted].
- Root-run discovery activity was observed through dash and env processes [redacted].
- A root-run dash process was classified as a sensitive-file tool and had a sensitive target; actual file contents read or changed are not established [redacted].
- A root-run shell and its child executed from shared resource [redacted].
Deterministic signals
An event-driven shell execution was observed in a protected workload without correlated HTTP evidence
26 observations · 12 processA previously correlated process lifecycle exited
36 observations · 12 processAn event-driven discovery command was observed in a protected workload without correlated HTTP evidence
4 observations · 4 processA process executed or interpreted content from an inventory-resolved resource attached to multiple workloads
26 observations · 11 process · 1 inventoryAn event-driven process targeted a sensitive file in a protected workload without correlated HTTP evidence
1 observations · 1 processExplicit uncertainty
- No HTTP evidence reference was available to the HTTP evidence tool, so the originating request, if any, and request-to-process causality remain unknown.
- No flow evidence reference was available to the flow evidence tool, so outbound communication, destination novelty, command-and-control, lateral movement, and data transfer cannot be assessed.
- The source key is a workload cluster rather than a verified person or remote actor identity.
- The bounded process summaries omit exact arguments and file paths; they establish process classes and sensitive targeting but not the precise commands, data accessed, or content changed.
- The common parent PID 2212046 could represent a legitimate application service, job runner, or administrative mechanism; its executable and authorization context are not available.
- Shared-resource execution is observed, but whether the resource content was malicious, who placed it there, and whether other attached workloads executed it are unresolved.
- There is no evidence here proving host escape, persistence, credential theft, lateral movement, command-and-control, or data exfiltration.
Recommended actions
- Temporarily restrict or isolate the affected workload if operationally safe while validating whether the repeated root shell activity was authorized.
- Identify PID 2212046, its service owner, deployment image, and expected behavior; compare the observed shell/discovery pattern with approved jobs and administrative activity.
- Preserve workload, process, orchestrator, and authentication logs covering 2026-08-28T22:31Z–22:58Z and correlate them with operator actions and job submissions.
- Inspect shared resource [redacted] for recent changes, provenance, integrity, and all workloads with access; prevent further execution if unauthorized.
- Determine the exact sensitive file targeted and verify access/change audit records. Rotate exposed credentials or secrets if access is confirmed or cannot be excluded.
- Review network telemetry for the affected workload during the incident window to determine whether any outbound connections or data transfers accompanied the process activity.
- If the behavior is confirmed legitimate, document the authorized parent process and command patterns and tune detections narrowly rather than suppressing root-shell monitoring broadly.