Live public case
Reconnaissance
Last activity Aug 18, 8:44:55 PM PDT
Evidence-grounded assessment
Not required
The evidence strongly supports real automated HTTP surface enumeration against target privatekind from one derived traffic cluster. The detector aggregated 356 requests spanning 173 unique paths, six methods, and eight path categories; verified samples show rapid POST, PATCH, PUT, and GET activity against distinct path hashes, with a mixture of 200, 404, 405, and 422 responses. This is highly consistent with reconnaissance, but maliciousness is not conclusive because authorization and source ownership are unknown and the incident also reports substantial authenticated traffic. Some requests returned 200, but status codes and body hashes alone do not prove state change, exploitation, or compromise. No cited process or flow events were available to assess downstream consequences.
Shared case lifecycle
Resolved · Authorized test
This read-only state comes from the same canonical workflow as the private operator console. Notes and append-only action history remain private.
Observed impact
- Observed impact is limited to broad probing and potential mapping of the target's HTTP/API surface.
- Several sampled requests received HTTP 200 responses, but the available summaries do not establish harmful state changes, command execution, persistence, outbound activity, or data loss.
Recommended actions
Attack timeline
1 incident threads
Resolution changes operator work, not the preserved attack evidence below.
- 1Reconnaissanceopen
The evidence strongly supports real automated HTTP surface enumeration against target privatekind from one derived traffic cluster. The detector aggregated 356 requests spanning 173 unique paths, six methods, and eight path categories; verified samples show rapid POST, PATCH, PUT, and GET activity against distinct path hashes, with a mixture of 200, 404, 405, and 422 responses. This is highly consistent with reconnaissance, but maliciousness is not conclusive because authorization and source ownership are unknown and the incident also reports substantial authenticated traffic. Some requests returned 200, but status codes and body hashes alone do not prove state change, exploitation, or compromise. No cited process or flow events were available to assess downstream consequences.