Sanitized live incident
Suspicious activity
Native source identity and targetable endpoints are private.
- Confidence
- 99%
- First seen
- Aug 27, 9:17:21 PM PDT
- Evidence through
- Aug 27, 9:20:53 PM PDT
- AI status
- Complete
Verified event-driven process telemetry confirms repeated root-context dash shell execution in the protected image-host workload, including discovery-class activity and two network-client-class shell executions. Matching lifecycle evidence shows sampled shells exited quickly, with both zero and nonzero outcomes. However, the incident provides no retrievable HTTP or flow evidence to establish an originating request, actor, actual outbound connection, exploitation, or compromise. This is materially suspicious and warrants urgent validation, but process execution alone cannot distinguish unauthorized activity from legitimate workload or administrative automation.
- Attack stage
- Execution and discovery; outbound-capable client spawning observed, with origin and intent unknown
- Model
- gpt-5.6-sol · 8 evidence calls
Observed impact
- Root-context shell processes executed inside the protected workload.
- Discovery-class processes were spawned in the workload.
- Network-client-class shell processes were spawned; an actual outbound connection was not established by available evidence.
- Sampled correlated shell processes exited, including both successful and unsuccessful outcomes.
Deterministic signals
An event-driven shell execution was observed in a protected workload without correlated HTTP evidence
21 observations · 12 processA previously correlated process lifecycle exited
22 observations · 12 processAn event-driven discovery command was observed in a protected workload without correlated HTTP evidence
2 observations · 2 processAn event-driven outbound-capable client was observed in a protected workload without correlated HTTP evidence
2 observations · 2 processExplicit uncertainty
- No HTTP evidence reference was available for retrieval, so no request, remote source, or request-to-process causality can be established.
- No flow evidence reference was available for retrieval, so network-client process execution does not prove an outbound connection, destination contact, command-and-control, or exfiltration.
- The bounded process summaries do not expose command arguments or shell contents, leaving the exact actions and intent unknown.
- The identity and purpose of parent PID 2212046 are not established by the available evidence.
- The workload source key is a derived cluster, not a guaranteed human or remote-actor identity.
- Available evidence does not establish host escape, persistence, lateral movement, data theft, or exploitation.
Recommended actions
- Urgently identify parent PID 2212046 and compare its activity with the workload's expected entrypoint, scheduler, health checks, and administrative automation.
- Review full process command lines, environment-independent audit records, and workload control-plane events for the incident window to determine what each dash process executed and who initiated it.
- Review egress, DNS, proxy, and conntrack records for the workload around [redacted]57Z to determine whether the network-client-class processes made connections.
- If the shell activity is unauthorized or cannot be promptly explained, isolate or replace the workload using approved containment procedures and preserve forensic telemetry.
- Review why the image-host workload runs these shells as root and reduce privileges or remove unnecessary shell/network utilities where operationally feasible.