Back to cases

Live public case

Reconnaissance

Last activity Aug 27, 10:13:55 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

Likely true positive for automated HTTP reconnaissance against target privatekind, not for compromise. The detector aggregated 335 requests spanning 128 unique paths, three methods, and eight path categories from one traffic cluster; sampled evidence includes repeated POSTs to one API-route hash receiving 429 responses and later GETs across distinct API-route hashes receiving 401 responses (HTTP refs [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). This strongly supports route/method enumeration. Authorization and intent remain unknown, however, and the detector facts report that 293 of 335 requests were authenticated, so the signal summary's “unauthenticated” wording is not uniformly applicable. No process or flow evidence is cited by this incident, so consequences beyond HTTP probing are not established.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Broad probing of the target's HTTP route and method surface was observed.
  • Available evidence does not establish command execution, outbound network consequences, persistence, lateral movement, or data loss.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Reconnaissanceopen

      Likely true positive for automated HTTP reconnaissance against target privatekind, not for compromise. The detector aggregated 335 requests spanning 128 unique paths, three methods, and eight path categories from one traffic cluster; sampled evidence includes repeated POSTs to one API-route hash receiving 429 responses and later GETs across distinct API-route hashes receiving 401 responses (HTTP refs [redacted], [redacted], [redacted], [redacted], [redacted], [redacted]). This strongly supports route/method enumeration. Authorization and intent remain unknown, however, and the detector facts report that 293 of 335 requests were authenticated, so the signal summary's “unauthenticated” wording is not uniformly applicable. No process or flow evidence is cited by this incident, so consequences beyond HTTP probing are not established.