Live public case
Reconnaissance
Last activity Aug 21, 11:21:24 PM PDT
Evidence-grounded assessment
Not required
The evidence strongly supports the detector's medium-severity reconnaissance classification: a single derived traffic cluster generated broad, unauthenticated HTTP route/method enumeration against target privatekind. The incident aggregate reports 65 requests across 48 unique paths, four methods, and seven path categories, while representative HTTP records show rapid probing of API endpoints with both 200 and 401 responses (for example, [redacted] and [redacted]). Authorization and actor identity remain unknown, so this could still be sanctioned testing or inventory activity. No process- or flow-plane references are cited by the incident, and the HTTP evidence does not establish exploitation or downstream compromise.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Observed impact is limited to application-surface probing; representative requests elicited both successful and authentication-required responses, which may reveal endpoint availability or access-control behavior [HTTP 6d585baf-d97d-4565-bt
- No execution, persistence, lateral movement, command-and-control, or data theft is established by the available evidence; the incident provides no process- or flow-plane event references for consequence analysis.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Reconnaissanceopen
The evidence strongly supports the detector's medium-severity reconnaissance classification: a single derived traffic cluster generated broad, unauthenticated HTTP route/method enumeration against target privatekind. The incident aggregate reports 65 requests across 48 unique paths, four methods, and seven path categories, while representative HTTP records show rapid probing of API endpoints with both 200 and 401 responses (for example, [redacted] and [redacted]). Authorization and actor identity remain unknown, so this could still be sanctioned testing or inventory activity. No process- or flow-plane references are cited by the incident, and the HTTP evidence does not establish exploitation or downstream compromise.