DEMO Read-only showcase seeded with synthetic data. Sign-in, reviewing, rules, retention and alerts are disabled. Browse every page and session freely. Install on your fleet →
Back to session
Sigtrace AI.Trace · Forensic session report

Session demo-heavy-activity

Agent claude-code on host dev-laptop-bill · 2m10s

Session ID
demo-heavy-activity
Agent
claude-code
Host
dev-laptop-bill
First seen
2026-04-22 16:14:21Z
Last seen
2026-04-22 16:16:31Z
Duration
2m10s
Events captured
64
Posted at
2026-04-22 22:14:21Z
Report generated
2026-04-23 10:20:25Z
Report ID
3a8907579c9d5b8e
Schema version
1
Live dashboard
https://demo.sigtrace.ai/ui/sessions/demo-heavy-activity
Verdict Low 2 shell spawns 4 network targets

Sensitive path hits · 0

No sensitive path hits.

Suspicious host queries · 0

No suspicious host queries.

Suspicious command lines · 0

No suspicious command lines.

Registry persistence · 0

No registry persistence writes.

Flagged image loads · 0

No flagged image loads.

Top processes · 4

ImageCount
C:\Program Files\Git\usr\bin\bash.exe1
C:\Program Files\nodejs\node.exe1
C:\Users\bill\AppData\Roaming\Claude\claude-code\2.1.111\claude.exe1
C:\Windows\System32\cmd.exe1

Top file opens · 7

PathCount
C:\work\shadowtrace\README.md9
C:\work\shadowtrace\go.mod8
C:\work\shadowtrace\cmd\etw-probe\main.go7
C:\work\shadowtrace\internal\storage\pgstore\store.go6
C:\work\shadowtrace\internal\summary\summary.go5
C:\work\shadowtrace\internal\server\ui.go4
C:\work\shadowtrace\internal\server\server.go3

File writes · 7

PathCount
C:\work\shadowtrace\README.md1
C:\work\shadowtrace\cmd\etw-probe\main.go1
C:\work\shadowtrace\go.mod1
C:\work\shadowtrace\internal\server\server.go1
C:\work\shadowtrace\internal\server\ui.go1
C:\work\shadowtrace\internal\storage\pgstore\store.go1
C:\work\shadowtrace\internal\summary\summary.go1

File renames / deletes

PathOpCount
C:\work\shadowtrace\internal\server\server.gorename1
C:\work\shadowtrace\scratch\old.txtdelete1

DNS queries · 5

QueryCount
api.anthropic.com1
deb.debian.org1
github.com1
proxy.golang.org1
registry.npmjs.org1

TCP targets · 4

TargetCount
104.16.132.229:4431
140.82.114.3:4431
34.107.221.82:4431
52.88.101.23:4431
End of report · Session demo-heavy-activity · Report 3a8907579c9d5b8e Generated 2026-04-23 10:20:25Z · schema 1