DEMO Read-only showcase seeded with synthetic data. Sign-in, reviewing, rules, retention and alerts are disabled. Browse every page and session freely. Install on your fleet →
Back to session
Sigtrace AI.Trace · Forensic session report

Session staging-ci-01-critical-1068961348

Agent claude-code on host staging-ci-01 · 1m28s

Session ID
staging-ci-01-critical-1068961348
Agent
claude-code
Host
staging-ci-01
First seen
2026-04-22 17:15:39Z
Last seen
2026-04-22 17:17:07Z
Duration
1m28s
Events captured
35
Posted at
2026-04-22 22:14:21Z
Report generated
2026-04-23 10:36:24Z
Report ID
dc073176f42a5ab9
Schema version
1
Live dashboard
https://demo.sigtrace.ai/ui/sessions/staging-ci-01-critical-1068961348
Verdict Critical 2 sensitive paths 1 suspicious host 2 registry hits 1 shell spawn 5 network targets

Sensitive path hits · 2

PathReasonOpProcessPidWhen
C:\Users\bill\.aws\config aws credentials open 3490 2026-04-22T17:17:03.66819715Z
C:\Users\bill\.aws\config aws credentials open 3490 2026-04-22T17:17:03.66819715Z

Suspicious host queries · 1

HostReason
transfer.shanonymous file drop

Suspicious command lines · 0

No suspicious command lines.

Registry persistence · 2

KeyValueOpReasonProcessPidWhen
\REGISTRY\USER\S-1-5-21-1000\Software\Microsoft\Windows\CurrentVersion\Run Updater set run key 9004 2026-04-22T17:17:07.66819715Z
\REGISTRY\USER\S-1-5-21-1000\Software\Microsoft\Windows\CurrentVersion\Run Updater set run key 9004 2026-04-22T17:17:07.66819715Z

Flagged image loads · 0

No flagged image loads.

Top processes · 2

ImageCount
C:\Users\bill\AppData\Roaming\Claude\claude-code\2.1.111\claude.exe1
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe1

Top file opens · 4

PathCount
C:\work\pipeline\pipeline\stages\ingest.py3
C:\work\pipeline\pipeline\stages\transform.py3
C:\work\pipeline\pyproject.toml3
C:\work\pipeline\tests\test_ingest.py3

File writes · 2

PathCount
C:\work\pipeline\Makefile1
C:\work\pipeline\tests\test_ingest.py1

File renames / deletes

No renames or deletes.

DNS queries · 6

QueryCount
transfer.sh2
api.anthropic.com1
deb.debian.org1
github.com1
proxy.golang.org1
raw.githubusercontent.com1

TCP targets · 4

TargetCount
104.16.132.229:4431
140.82.114.3:4431
151.101.0.223:4431
52.88.101.23:4431

UDP targets · 1

TargetCount
45.137.21.9:534132
End of report · Session staging-ci-01-critical-1068961348 · Report dc073176f42a5ab9 Generated 2026-04-23 10:36:24Z · schema 1