DEMO Read-only showcase seeded with synthetic data. Sign-in, reviewing, rules, retention and alerts are disabled. Browse every page and session freely. Install on your fleet →
Back to session
Sigtrace AI.Trace · Forensic session report

Session staging-ci-01-critical-59535636

Agent claude-code on host staging-ci-01 · 1m28s

Session ID
staging-ci-01-critical-59535636
Agent
claude-code
Host
staging-ci-01
First seen
2026-04-20 23:44:16Z
Last seen
2026-04-20 23:45:44Z
Duration
1m28s
Events captured
35
Posted at
2026-04-22 22:14:21Z
Report generated
2026-04-23 10:34:57Z
Report ID
5e2a7f566bcdc019
Schema version
1
Live dashboard
https://demo.sigtrace.ai/ui/sessions/staging-ci-01-critical-59535636
Verdict Critical 2 sensitive paths 1 suspicious host 2 registry hits 1 shell spawn 4 network targets

Sensitive path hits · 2

PathReasonOpProcessPidWhen
C:\Users\bill\.kube\config kube config open 8158 2026-04-20T23:45:40.591538552Z
C:\Users\bill\.kube\config kube config open 8158 2026-04-20T23:45:40.591538552Z

Suspicious host queries · 1

HostReason
anonfiles.comanonymous file drop

Suspicious command lines · 0

No suspicious command lines.

Registry persistence · 2

KeyValueOpReasonProcessPidWhen
\REGISTRY\USER\S-1-5-21-1000\Software\Microsoft\Windows\CurrentVersion\Run Updater set run key 9099 2026-04-20T23:45:44.591538552Z
\REGISTRY\USER\S-1-5-21-1000\Software\Microsoft\Windows\CurrentVersion\Run Updater set run key 9099 2026-04-20T23:45:44.591538552Z

Flagged image loads · 0

No flagged image loads.

Top processes · 2

ImageCount
C:\Users\bill\AppData\Roaming\Claude\claude-code\2.1.111\claude.exe1
C:\Windows\System32\cmd.exe1

Top file opens · 4

PathCount
C:\work\pipeline\tests\test_ingest.py5
C:\work\pipeline\pipeline\stages\ingest.py3
C:\work\pipeline\pipeline\stages\transform.py3
C:\work\pipeline\pyproject.toml3

File writes · 1

PathCount
C:\work\pipeline\Makefile1

File renames / deletes

No renames or deletes.

DNS queries · 4

QueryCount
anonfiles.com2
github.com1
pypi.org1
raw.githubusercontent.com1

TCP targets · 3

TargetCount
140.82.114.3:4431
151.101.0.223:4431
192.229.211.108:4431

UDP targets · 1

TargetCount
45.137.21.9:534132
End of report · Session staging-ci-01-critical-59535636 · Report 5e2a7f566bcdc019 Generated 2026-04-23 10:34:57Z · schema 1