Back to evidence

Sanitized live incident

Suspicious activity

Native source identity and targetable endpoints are private.

criticalopen
Confidence
99%
First seen
Aug 27, 9:17:21 PM PDT
Evidence through
Aug 27, 9:20:53 PM PDT
AI status
Complete
Indeterminate84% confidence

Verified event-driven process telemetry confirms repeated root-context dash shell execution in the protected image-host workload, including discovery-class activity and two network-client-class shell executions. Matching lifecycle evidence shows sampled shells exited quickly, with both zero and nonzero outcomes. However, the incident provides no retrievable HTTP or flow evidence to establish an originating request, actor, actual outbound connection, exploitation, or compromise. This is materially suspicious and warrants urgent validation, but process execution alone cannot distinguish unauthorized activity from legitimate workload or administrative automation.

Attack stage
Execution and discovery; outbound-capable client spawning observed, with origin and intent unknown
Model
gpt-5.6-sol · 8 evidence calls

Observed impact

  • Root-context shell processes executed inside the protected workload.
  • Discovery-class processes were spawned in the workload.
  • Network-client-class shell processes were spawned; an actual outbound connection was not established by available evidence.
  • Sampled correlated shell processes exited, including both successful and unsuccessful outcomes.

Deterministic signals

Process.observed shell spawn99%

An event-driven shell execution was observed in a protected workload without correlated HTTP evidence

21 observations · 12 process
Process.correlated exit99%

A previously correlated process lifecycle exited

22 observations · 12 process
Process.observed discovery command88%

An event-driven discovery command was observed in a protected workload without correlated HTTP evidence

2 observations · 2 process
Process.observed network client87%

An event-driven outbound-capable client was observed in a protected workload without correlated HTTP evidence

2 observations · 2 process

Explicit uncertainty

  • No HTTP evidence reference was available for retrieval, so no request, remote source, or request-to-process causality can be established.
  • No flow evidence reference was available for retrieval, so network-client process execution does not prove an outbound connection, destination contact, command-and-control, or exfiltration.
  • The bounded process summaries do not expose command arguments or shell contents, leaving the exact actions and intent unknown.
  • The identity and purpose of parent PID 2212046 are not established by the available evidence.
  • The workload source key is a derived cluster, not a guaranteed human or remote-actor identity.
  • Available evidence does not establish host escape, persistence, lateral movement, data theft, or exploitation.

Recommended actions

  1. Urgently identify parent PID 2212046 and compare its activity with the workload's expected entrypoint, scheduler, health checks, and administrative automation.
  2. Review full process command lines, environment-independent audit records, and workload control-plane events for the incident window to determine what each dash process executed and who initiated it.
  3. Review egress, DNS, proxy, and conntrack records for the workload around [redacted]57Z to determine whether the network-client-class processes made connections.
  4. If the shell activity is unauthorized or cannot be promptly explained, isolate or replace the workload using approved containment procedures and preserve forensic telemetry.
  5. Review why the image-host workload runs these shells as root and reduce privileges or remove unnecessary shell/network utilities where operationally feasible.