Back to cases

Live public case

Reconnaissance

Last activity Aug 30, 10:44:16 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

The incident is best assessed as likely true-positive application-surface reconnaissance. The detector aggregated 64 requests from one traffic/workload cluster across 51 unique paths, five HTTP methods, and six path categories, with 53 rejected responses. The verified samples show rapid requests to distinct route hashes, mixed GET/POST usage, and repeated 401/422 responses, consistent with automated route and method enumeration. Two sampled requests returned HTTP 200, but status alone does not establish exploitation or compromise. Authorization is unknown, so sanctioned security testing or inventory remains a plausible alternative. No process or flow evidence is cited by this incident, so no execution, outbound consequence, persistence, lateral movement, or data loss is established.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Observed impact is limited to probing and potential mapping of the application's exposed routes and method behavior; no post-exploitation consequence is established.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Reconnaissanceopen

      The incident is best assessed as likely true-positive application-surface reconnaissance. The detector aggregated 64 requests from one traffic/workload cluster across 51 unique paths, five HTTP methods, and six path categories, with 53 rejected responses. The verified samples show rapid requests to distinct route hashes, mixed GET/POST usage, and repeated 401/422 responses, consistent with automated route and method enumeration. Two sampled requests returned HTTP 200, but status alone does not establish exploitation or compromise. Authorization is unknown, so sanctioned security testing or inventory remains a plausible alternative. No process or flow evidence is cited by this incident, so no execution, outbound consequence, persistence, lateral movement, or data loss is established.