Live public case
Reconnaissance
Last activity Aug 30, 10:44:16 PM PDT
Evidence-grounded assessment
Not required
The incident is best assessed as likely true-positive application-surface reconnaissance. The detector aggregated 64 requests from one traffic/workload cluster across 51 unique paths, five HTTP methods, and six path categories, with 53 rejected responses. The verified samples show rapid requests to distinct route hashes, mixed GET/POST usage, and repeated 401/422 responses, consistent with automated route and method enumeration. Two sampled requests returned HTTP 200, but status alone does not establish exploitation or compromise. Authorization is unknown, so sanctioned security testing or inventory remains a plausible alternative. No process or flow evidence is cited by this incident, so no execution, outbound consequence, persistence, lateral movement, or data loss is established.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Observed impact is limited to probing and potential mapping of the application's exposed routes and method behavior; no post-exploitation consequence is established.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Reconnaissanceopen
The incident is best assessed as likely true-positive application-surface reconnaissance. The detector aggregated 64 requests from one traffic/workload cluster across 51 unique paths, five HTTP methods, and six path categories, with 53 rejected responses. The verified samples show rapid requests to distinct route hashes, mixed GET/POST usage, and repeated 401/422 responses, consistent with automated route and method enumeration. Two sampled requests returned HTTP 200, but status alone does not establish exploitation or compromise. Authorization is unknown, so sanctioned security testing or inventory remains a plausible alternative. No process or flow evidence is cited by this incident, so no execution, outbound consequence, persistence, lateral movement, or data loss is established.