Back to cases

Live public case

Reconnaissance

Last activity Aug 30, 12:04:24 AM PDT

mediumNot required

Evidence-grounded assessment

Not required

The evidence supports a real, sustained web-surface enumeration pattern against target privatekind: the detector-derived facts report 1,205 requests over 512 connections, 128 unique paths, four methods, and eight path categories. Verified HTTP samples from the cited cluster show requests to multiple path hashes/categories with mixed 200, 400, 403, and 404 responses, consistent with route probing. This is best assessed as likely true-positive reconnaissance, not confirmed compromise. Authorization and intent remain unresolved, and the incident contains a material semantic inconsistency: its summary calls the activity unauthenticated while its own facts count 1,057 authenticated requests. No process- or flow-plane evidence is cited, so execution, persistence, outbound activity, or other post-reconnaissance consequences are not established.

Protected workloads
One protected workload
Progression
Within-workload activity
Severity basis
Maximum incident posture

Observed impact

  • Observed impact is limited to sustained probing of the target's HTTP surface; no post-reconnaissance consequence is established by the cited evidence.
  • At least one cited probe received an HTTP 200 response, indicating some requested resource was served, but status alone does not establish sensitive exposure or exploit success.

Recommended actions

    Attack timeline

    1 incident threads

    Live progression remains visible; PII, native endpoints, hashes, and private identities do not.

    1. 1
      Reconnaissanceopen

      The evidence supports a real, sustained web-surface enumeration pattern against target privatekind: the detector-derived facts report 1,205 requests over 512 connections, 128 unique paths, four methods, and eight path categories. Verified HTTP samples from the cited cluster show requests to multiple path hashes/categories with mixed 200, 400, 403, and 404 responses, consistent with route probing. This is best assessed as likely true-positive reconnaissance, not confirmed compromise. Authorization and intent remain unresolved, and the incident contains a material semantic inconsistency: its summary calls the activity unauthenticated while its own facts count 1,057 authenticated requests. No process- or flow-plane evidence is cited, so execution, persistence, outbound activity, or other post-reconnaissance consequences are not established.