Live public case
Reconnaissance
Last activity Aug 30, 12:13:28 PM PDT
Evidence-grounded assessment
Not required
Likely true positive for automated HTTP reconnaissance against target privatekind. The cited HTTP sequence supports rapid, broad, unauthenticated surface enumeration: the detector aggregated 64 requests to 64 unique paths across two methods and seven path categories in roughly 2.74 seconds, with 52 rejected responses. Verified examples have distinct path hashes, complete captures, empty request bodies, and mostly uniform 404 responses; the root request returned 200. This establishes probing behavior, not exploit success. Authorization is unknown, and no process or flow evidence is cited by the incident, so no workload compromise or follow-on network consequence is established.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Observed impact is limited to unauthenticated HTTP surface probing and receipt of server responses; no execution, persistence, lateral movement, egress consequence, or data theft is established by the available cited evidence.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Reconnaissanceopen
Likely true positive for automated HTTP reconnaissance against target privatekind. The cited HTTP sequence supports rapid, broad, unauthenticated surface enumeration: the detector aggregated 64 requests to 64 unique paths across two methods and seven path categories in roughly 2.74 seconds, with 52 rejected responses. Verified examples have distinct path hashes, complete captures, empty request bodies, and mostly uniform 404 responses; the root request returned 200. This establishes probing behavior, not exploit success. Authorization is unknown, and no process or flow evidence is cited by the incident, so no workload compromise or follow-on network consequence is established.