Back to cases

Live public case

Reconnaissance

Last activity Aug 28, 8:57:27 AM PDT

mediumNot required

Evidence-grounded assessment

Not required

The bounded HTTP evidence supports the detector's reconnaissance classification: one source cluster sent varied HEAD, GET, and POST requests across root, API, and other route categories on target privatekind during the cited interval [redacted]. Responses varied among 200, 401, 404, 422, and 500, and several GETs returned sizable bodies, indicating that some probed resources responded with content [redacted]. This is strong evidence of surface enumeration, but authorization and operator identity are unknown. No cited process or flow events were available to assess consequences beyond HTTP reconnaissance.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Potential route and content discovery: multiple GET probes received HTTP 200 with response bodies of 112,594, 33,326, 21,848, 8,525, and 128,022 bytes; the sensitivity of that content is unknown [HTTP [redacted], f

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Reconnaissanceopen

      The bounded HTTP evidence supports the detector's reconnaissance classification: one source cluster sent varied HEAD, GET, and POST requests across root, API, and other route categories on target privatekind during the cited interval [redacted]. Responses varied among 200, 401, 404, 422, and 500, and several GETs returned sizable bodies, indicating that some probed resources responded with content [redacted]. This is strong evidence of surface enumeration, but authorization and operator identity are unknown. No cited process or flow events were available to assess consequences beyond HTTP reconnaissance.