-
root sensitive
C:\Users\bill\AppData\Roaming\Claude\claude-code\2.1.111\claude.exepid9900·2026-04-22T20:14:21.406495887Z· still running2 opens 1 writes 1 DNS 2 sensitivetop activity for this pid
OpensC:\Users\ci\.aws\credentials1 C:\Users\ci\.ssh\id_rsa1 WritesC:\Users\ci\AppData\Local\Temp\svc-updater.exe1 DNSpastebin.com1 SensitiveC:\Users\ci\.aws\credentialsaws credentials · open C:\Users\ci\.ssh\id_rsassh keys · open -
root shell
C:\Windows\System32\cmd.exepid9100·2026-04-22T20:14:23.406495887Z· still running2 TCPtop activity for this pid
TCP185.220.101.42:4444 (udp)1 45.137.21.9:53413 (udp)1 -
root shell
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepid9101·2026-04-22T20:14:39.406495887Z· still runningpowershell -EncodedCommand JABjACAAPQAgACIASABlAGwAbABvACIAOwAgACQAYwA= -
root
C:\Windows\System32\sc.exepid9102·2026-04-22T20:14:41.406495887Z· still runningsc.exe create SvcUpdater binPath= "C:\Users\ci\AppData\Local\Temp\svc-updater.exe" start= auto
Session
demo-critical-exfil
No notes yet. Leave the first one so the next reviewer inherits the context.