Back to evidence

Sanitized live incident

Suspicious activity

Native source identity and targetable endpoints are private.

criticalopen
Confidence
99%
First seen
Aug 23, 2:39:38 PM PDT
Evidence through
Aug 23, 2:53:36 PM PDT
AI status
Complete
Indeterminate93% confidence

Verified process telemetry establishes repeated event-driven, root-context shell execution in the protected workload and one root process classified as both a shell and network client. This is materially suspicious, but the bounded evidence does not establish whether the activity was authorized workload/administrative automation or malicious execution. No cited HTTP or flow-plane event was available for inspection, so there is no supported request-to-process origin or observed network connection. The incident's critical detector output is therefore not dismissed, but exploitation or compromise cannot be adjudicated from the available evidence.

Attack stage
Execution observed; possible outbound-capable tooling, origin undetermined
Model
gpt-5.6-sol · 9 evidence calls

Observed impact

  • Root-context shell processes executed inside the protected workload.
  • A root process with shell and network-client classifications was spawned; no successful outbound connection is established.
  • Observed shell lifecycles included both successful and unsuccessful exits; persistence or broader compromise is not established.

Deterministic signals

Process.observed shell spawn99%

An event-driven shell execution was observed in a protected workload without correlated HTTP evidence

69 observations · 12 process
Process.correlated exit99%

A previously correlated process lifecycle exited

69 observations · 12 process
Process.observed network client87%

An event-driven outbound-capable client was observed in a protected workload without correlated HTTP evidence

1 observations · 1 process

Explicit uncertainty

  • No HTTP-plane evidence reference was cited by the incident for bounded inspection; consequently, the process origin cannot be tied to an HTTP request or remote actor.
  • No flow-plane evidence reference was cited by the incident for bounded inspection; the network_client classification does not prove that a connection was attempted or completed.
  • The verified summaries exclude exact arguments and commands, so the shells' intended operations and the network client's target are unknown.
  • The common parent PID is observed, but its executable, owner, and role are not established by the available summaries.
  • The source key represents a workload cluster, not a guaranteed human or agent identity.
  • No evidence provided here proves persistence, host escape, lateral movement, command-and-control, or data theft.

Recommended actions

  1. Identify parent PID 1321728 and compare this shell pattern with the workload's deployment specification, entrypoint, health checks, scheduled jobs, and approved administrative automation.
  2. Review retained workload and orchestration audit logs around 21:39–21:54 UTC to determine who or what initiated the process tree.
  3. Review independent egress telemetry for the workload around [redacted] UTC; do not infer a connection from process classification alone.
  4. If the parent or commands are unauthorized, contain or replace the workload, preserve forensic telemetry, and investigate adjacent credentials and secrets before rotation.
  5. Reduce the workload from root where operationally feasible and constrain allowed child processes and egress destinations.