Back to evidence

Sanitized live incident

Suspicious activity

Native source identity and targetable endpoints are private.

criticalopen
Confidence
99%
First seen
Aug 30, 10:34:52 AM PDT
Evidence through
Aug 30, 11:09:25 AM PDT
AI status
Complete
Indeterminate87% confidence

Process telemetry conclusively shows repeated root-level dash execution in the processor workload, including discovery-classified shells and a final root dash→id parent-child chain [redacted]. Exact PID-matched lifecycle evidence also shows sampled shells exiting, generally successfully [redacted]. These are real execution consequences, but the bounded evidence does not establish whether they were authorized processor behavior or malicious activity. No usable HTTP or flow evidence was cited, so initial access, actor, request causality, network consequences, and compromise cannot be determined.

Attack stage
Execution and discovery-like activity observed; initial access and malicious intent unproven
Model
gpt-5.6-sol · 11 evidence calls

Observed impact

  • Root-level shell processes executed inside the workload [redacted].
  • A root id discovery process was spawned by a root dash parent [redacted].
  • Sampled shell processes were transient and exited, with exact PID-matched examples returning zero [redacted].

Deterministic signals

Process.observed shell spawn99%

An event-driven shell execution was observed in a protected workload without correlated HTTP evidence

1939 observations · 12 process
Process.correlated exit99%

A previously correlated process lifecycle exited

1940 observations · 12 process
Process.observed discovery command88%

An event-driven discovery command was observed in a protected workload without correlated HTTP evidence

12 observations · 12 process

Explicit uncertainty

  • The originating action and actor are unknown; the source key identifies a workload cluster, not a person or remote agent.
  • HTTP and flow evidence queries could not return summaries because this incident cites no events in those planes; request causality and network consequences therefore cannot be evaluated.
  • The bounded summaries exclude exact arguments and command bodies, so the purpose of most dash invocations is unknown.
  • Authorization and expected behavior for parent PID 2212455 are not available; repetitive shells could represent legitimate processor automation, administrative activity, or malicious execution.
  • No cited evidence establishes persistence, host escape, lateral movement, command-and-control, or data theft.

Recommended actions

  1. Validate parent PID 2212455, its owning processor component, and the corresponding job or task records against the approved workload design.
  2. Review orchestration and administrative audit logs around [redacted]–[redacted]25Z to determine who or what initiated the shell activity.
  3. If the dash and id executions are unauthorized, contain and replace the workload instance, preserve relevant telemetry, and investigate the image and task inputs before restoration.
  4. Reduce risk by running the processor as a non-root identity and limiting shell availability where operationally feasible.
  5. Review independent network telemetry for the same workload and interval because no flow evidence is cited here.
  6. Tune the detector only after confirming that this exact parent/child pattern is expected and documented.