DEMO Read-only showcase seeded with synthetic data. Sign-in, reviewing, rules, retention and alerts are disabled. Browse every page and session freely. Install on your fleet →
Back to session
Sigtrace AI.Trace · Forensic session report

Session demo-critical-exfil

Agent claude-code on host staging-ci-01 · 20s

Session ID
demo-critical-exfil
Agent
claude-code
Host
staging-ci-01
First seen
2026-04-22 20:14:21Z
Last seen
2026-04-22 20:14:41Z
Duration
20s
Events captured
12
Posted at
2026-04-22 22:14:21Z
Report generated
2026-04-23 10:26:31Z
Report ID
ec94d1573d558bd7
Schema version
1
Live dashboard
https://demo.sigtrace.ai/ui/sessions/demo-critical-exfil
Verdict Critical 2 sensitive paths 1 suspicious host 2 suspicious cmdlines 1 flagged load 1 registry hit 2 shell spawns 2 network targets

Sensitive path hits · 2

PathReasonOpProcessPidWhen
C:\Users\ci\.aws\credentials aws credentials open C:\Users\bill\AppData\Roaming\Claude\claude-code\2.1.111\claude.exe 9900 2026-04-22T20:14:25.406495887Z
C:\Users\ci\.ssh\id_rsa ssh keys open C:\Users\bill\AppData\Roaming\Claude\claude-code\2.1.111\claude.exe 9900 2026-04-22T20:14:26.406495887Z

Suspicious host queries · 1

HostReason
pastebin.compaste site

Suspicious command lines · 2

CmdlineReasonProcessPidWhen
powershell -EncodedCommand JABjACAAPQAgACIASABlAGwAbABvACIAOwAgACQAYwA=
$c = "Hello"; $c
powershell encoded command C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 9101 2026-04-22T20:14:39.406495887Z
sc.exe create SvcUpdater binPath= "C:\Users\ci\AppData\Local\Temp\svc-updater.exe" start= auto service install C:\Windows\System32\sc.exe 9102 2026-04-22T20:14:41.406495887Z

Registry persistence · 1

KeyValueOpReasonProcessPidWhen
\REGISTRY\USER\S-1-5-21-1000\Software\Microsoft\Windows\CurrentVersion\Run SvcUpdater set run key 9100 2026-04-22T20:14:33.406495887Z

Flagged image loads · 1

ImageReasonProcessPidWhen
C:\Users\ci\AppData\Local\Temp\svc-updater.exe session-written C:\Windows\System32\cmd.exe 9100 2026-04-22T20:14:31.406495887Z

Top processes · 4

ImageCount
C:\Users\bill\AppData\Roaming\Claude\claude-code\2.1.111\claude.exe1
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe1
C:\Windows\System32\cmd.exe1
C:\Windows\System32\sc.exe1

Top file opens · 0

No file opens captured.

File writes · 1

PathCount
C:\Users\ci\AppData\Local\Temp\svc-updater.exe1

File renames / deletes

No renames or deletes.

DNS queries · 1

QueryCount
pastebin.com1

TCP targets · 0

No TCP connections.

UDP targets · 2

TargetCount
185.220.101.42:44441
45.137.21.9:534131
End of report · Session demo-critical-exfil · Report ec94d1573d558bd7 Generated 2026-04-23 10:26:31Z · schema 1