Back to evidence

Sanitized live incident

Suspicious activity

Native source identity and targetable endpoints are private.

criticalopen
Confidence
99%
First seen
Aug 28, 3:31:17 PM PDT
Evidence through
Aug 28, 3:57:47 PM PDT
AI status
Complete
Likely true positive86% confidence

Likely true positive for suspicious workload-level execution, but not a proven externally initiated exploit. Event-driven telemetry directly observed repeated root-run dash shells, discovery activity, a sensitive-file-targeting shell, and execution from an inventory-resolved shared resource in the same workload context [redacted]. The repeated common parent PID may indicate an application service or administrative automation rather than a remote actor, and no HTTP or flow evidence was available to establish origin, request-to-process causality, or network consequences. At least one observed shell had an exact exit event with a zero outcome; that establishes process completion only, not benign intent or exploit causality [redacted].

Attack stage
Workload execution and discovery with sensitive-file targeting and shared-resource execution
Model
gpt-5.6-sol · 14 evidence calls

Observed impact

  • A root-run dash shell executed inside the protected workload [redacted].
  • Root-run discovery activity was observed through dash and env processes [redacted].
  • A root-run dash process was classified as a sensitive-file tool and had a sensitive target; actual file contents read or changed are not established [redacted].
  • A root-run shell and its child executed from shared resource [redacted].

Deterministic signals

Process.observed shell spawn99%

An event-driven shell execution was observed in a protected workload without correlated HTTP evidence

26 observations · 12 process
Process.correlated exit99%

A previously correlated process lifecycle exited

36 observations · 12 process
Process.observed discovery command88%

An event-driven discovery command was observed in a protected workload without correlated HTTP evidence

4 observations · 4 process
Process.shared resource activity92%

A process executed or interpreted content from an inventory-resolved resource attached to multiple workloads

26 observations · 11 process · 1 inventory
Process.observed sensitive file command99%

An event-driven process targeted a sensitive file in a protected workload without correlated HTTP evidence

1 observations · 1 process

Explicit uncertainty

  • No HTTP evidence reference was available to the HTTP evidence tool, so the originating request, if any, and request-to-process causality remain unknown.
  • No flow evidence reference was available to the flow evidence tool, so outbound communication, destination novelty, command-and-control, lateral movement, and data transfer cannot be assessed.
  • The source key is a workload cluster rather than a verified person or remote actor identity.
  • The bounded process summaries omit exact arguments and file paths; they establish process classes and sensitive targeting but not the precise commands, data accessed, or content changed.
  • The common parent PID 2212046 could represent a legitimate application service, job runner, or administrative mechanism; its executable and authorization context are not available.
  • Shared-resource execution is observed, but whether the resource content was malicious, who placed it there, and whether other attached workloads executed it are unresolved.
  • There is no evidence here proving host escape, persistence, credential theft, lateral movement, command-and-control, or data exfiltration.

Recommended actions

  1. Temporarily restrict or isolate the affected workload if operationally safe while validating whether the repeated root shell activity was authorized.
  2. Identify PID 2212046, its service owner, deployment image, and expected behavior; compare the observed shell/discovery pattern with approved jobs and administrative activity.
  3. Preserve workload, process, orchestrator, and authentication logs covering 2026-08-28T22:31Z–22:58Z and correlate them with operator actions and job submissions.
  4. Inspect shared resource [redacted] for recent changes, provenance, integrity, and all workloads with access; prevent further execution if unauthorized.
  5. Determine the exact sensitive file targeted and verify access/change audit records. Rotate exposed credentials or secrets if access is confirmed or cannot be excluded.
  6. Review network telemetry for the affected workload during the incident window to determine whether any outbound connections or data transfers accompanied the process activity.
  7. If the behavior is confirmed legitimate, document the authorized parent process and command patterns and tune detections narrowly rather than suppressing root-shell monitoring broadly.