Back to evidence

Sanitized live incident

Suspicious activity

Native source identity and targetable endpoints are private.

criticalopen
Confidence
99%
First seen
Aug 27, 7:54:16 PM PDT
Evidence through
Aug 27, 7:57:20 PM PDT
AI status
Complete
Indeterminate95% confidence

Process telemetry confirms repeated, short-lived root shell execution in the protected image-host workload, including nested dash/bash chains. Exact lifecycle evidence shows the cited processes exited with zero outcomes. However, the incident contains no correlated HTTP or flow evidence, and the available argument-free process summaries do not reveal commands, initiating action, or actor. The detector's critical suspicious-activity result is therefore supported as an observation of root shell spawning, but the evidence is insufficient to determine whether this was exploitation or expected workload/administrative automation.

Attack stage
Execution: root shell processes observed; initiating vector and malicious intent undetermined
Model
gpt-5.6-sol · 10 evidence calls

Observed impact

  • Ten shell processes were observed executing with root privileges inside the workload.
  • The cited shell processes subsequently exited with zero outcomes; no enduring process impact is demonstrated.
  • No evidence provided establishes persistence, host escape, lateral movement, command-and-control, or data theft.

Deterministic signals

Process.observed shell spawn99%

An event-driven shell execution was observed in a protected workload without correlated HTTP evidence

14 observations · 12 process
Process.correlated exit99%

A previously correlated process lifecycle exited

14 observations · 12 process

Explicit uncertainty

  • No incident-cited HTTP evidence was available to identify a request, remote source, exploit attempt, or request-to-process relationship.
  • No incident-cited flow evidence was available to evaluate outbound communication or destination novelty.
  • Argument-free process summaries do not expose the executed commands, arguments, environment, or resulting file/system changes.
  • The stable outer parent process is not identified by executable or workload function in the available summaries, so expected image-host automation cannot be distinguished from unauthorized activity.
  • The source key is a workload cluster and must not be treated as a human or remote actor identity.
  • Zero exit outcomes show process completion but do not establish that commands were benign or that they had no side effects.

Recommended actions

  1. Validate the shell pattern and the stable outer parent process against expected image-host startup, health-check, image-processing, and administrative automation.
  2. Review workload/orchestrator audit logs and deployment changes for 2026-08-28T02[redacted]16Z–[redacted]19Z to identify the initiating principal and intended commands.
  3. Preserve relevant workload logs and filesystem/runtime state before restart if the activity is not immediately attributable to approved automation.
  4. If the activity is unauthorized or cannot be promptly explained, contain the workload according to incident-response policy and redeploy it from a trusted image after collecting evidence.
  5. Increase monitoring for recurrence and correlate future shell executions with authenticated control-plane actions, HTTP telemetry, file changes, and network flows.