Back to cases

Live public case

Reconnaissance

Last activity Aug 21, 11:21:24 PM PDT

mediumNot required

Evidence-grounded assessment

Not required

The evidence strongly supports the detector's medium-severity reconnaissance classification: a single derived traffic cluster generated broad, unauthenticated HTTP route/method enumeration against target privatekind. The incident aggregate reports 65 requests across 48 unique paths, four methods, and seven path categories, while representative HTTP records show rapid probing of API endpoints with both 200 and 401 responses (for example, [redacted] and [redacted]). Authorization and actor identity remain unknown, so this could still be sanctioned testing or inventory activity. No process- or flow-plane references are cited by the incident, and the HTTP evidence does not establish exploitation or downstream compromise.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Observed impact is limited to application-surface probing; representative requests elicited both successful and authentication-required responses, which may reveal endpoint availability or access-control behavior [HTTP 6d585baf-d97d-4565-bt
  • No execution, persistence, lateral movement, command-and-control, or data theft is established by the available evidence; the incident provides no process- or flow-plane event references for consequence analysis.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Reconnaissanceopen

      The evidence strongly supports the detector's medium-severity reconnaissance classification: a single derived traffic cluster generated broad, unauthenticated HTTP route/method enumeration against target privatekind. The incident aggregate reports 65 requests across 48 unique paths, four methods, and seven path categories, while representative HTTP records show rapid probing of API endpoints with both 200 and 401 responses (for example, [redacted] and [redacted]). Authorization and actor identity remain unknown, so this could still be sanctioned testing or inventory activity. No process- or flow-plane references are cited by the incident, and the HTTP evidence does not establish exploitation or downstream compromise.