Live public case
Reconnaissance
Last activity Aug 30, 12:04:24 AM PDT
Evidence-grounded assessment
Not required
The evidence supports a real, sustained web-surface enumeration pattern against target privatekind: the detector-derived facts report 1,205 requests over 512 connections, 128 unique paths, four methods, and eight path categories. Verified HTTP samples from the cited cluster show requests to multiple path hashes/categories with mixed 200, 400, 403, and 404 responses, consistent with route probing. This is best assessed as likely true-positive reconnaissance, not confirmed compromise. Authorization and intent remain unresolved, and the incident contains a material semantic inconsistency: its summary calls the activity unauthenticated while its own facts count 1,057 authenticated requests. No process- or flow-plane evidence is cited, so execution, persistence, outbound activity, or other post-reconnaissance consequences are not established.
- Protected workloads
- One protected workload
- Progression
- Within-workload activity
- Severity basis
- Maximum incident posture
Observed impact
- Observed impact is limited to sustained probing of the target's HTTP surface; no post-reconnaissance consequence is established by the cited evidence.
- At least one cited probe received an HTTP 200 response, indicating some requested resource was served, but status alone does not establish sensitive exposure or exploit success.
Recommended actions
Attack timeline
1 incident threads
Live progression remains visible; PII, native endpoints, hashes, and private identities do not.
- 1Reconnaissanceopen
The evidence supports a real, sustained web-surface enumeration pattern against target privatekind: the detector-derived facts report 1,205 requests over 512 connections, 128 unique paths, four methods, and eight path categories. Verified HTTP samples from the cited cluster show requests to multiple path hashes/categories with mixed 200, 400, 403, and 404 responses, consistent with route probing. This is best assessed as likely true-positive reconnaissance, not confirmed compromise. Authorization and intent remain unresolved, and the incident contains a material semantic inconsistency: its summary calls the activity unauthenticated while its own facts count 1,057 authenticated requests. No process- or flow-plane evidence is cited, so execution, persistence, outbound activity, or other post-reconnaissance consequences are not established.