Back to evidence

Sanitized live incident

Reconnaissance

Native source identity and targetable endpoints are private.

mediumopen
Confidence
92%
First seen
Aug 27, 8:33:50 PM PDT
Evidence through
Aug 28, 2:47:59 AM PDT
AI status
Complete
Likely true positive90% confidence

The incident is strongly supported as broad, unauthenticated HTTP surface enumeration against target privatekind. The detector aggregated 75 requests across 48 unique paths, two methods, six path categories, and 46 connections from one derived source cluster; the verified samples show rapid HEAD/GET probing of distinct path hashes with mixed 200, 404, and 500 responses. Multiple 200 responses indicate that some probed routes returned content, but status codes and response sizes do not establish exploitation or sensitive-data exposure. No process- or flow-plane evidence is cited by this incident, so consequences beyond reconnaissance cannot be assessed. Because authorization and source identity are unknown, sanctioned scanning remains a material alternative.

Attack stage
Reconnaissance / application surface discovery
Model
gpt-5.6-sol · 15 evidence calls

Observed impact

  • Observed impact is limited to application-route and method discovery, including identification of routes that returned HTTP 200 responses.
  • No post-reconnaissance consequence is established; execution, persistence, lateral movement, command-and-control, and data theft are not demonstrated by the cited evidence.

Deterministic signals

Http.surface enumeration92%

Broad unauthenticated route and HTTP method enumeration observed

4262 observations · 12 http

Explicit uncertainty

  • The source key is a traffic/workload cluster, not a proven human or agent identity; it may represent a proxy, NAT gateway, or multiple workers.
  • Network evidence does not establish whether this activity was authorized security testing, benign inventory collection, or hostile reconnaissance.
  • The bounded HTTP summaries exclude exact paths and response contents, so the sensitivity of discovered routes and returned data cannot be determined.
  • No process- or flow-plane evidence references are cited by this incident. Queries using the incident's HTTP event IDs were rejected as not cited in those planes, leaving post-request execution and network consequences unassessed.
  • HTTP status alone does not establish exploit success or failure; no server-generated command output is available in the bounded summaries.

Recommended actions

  1. Validate whether the source cluster and time window correspond to an approved scanner, penetration test, monitoring system, or inventory job.
  2. Review retained application and gateway logs for the full set of path hashes, route ownership, and response sensitivity, especially distinct routes returning 200 and the route returning 500.
  3. If unauthorized, apply proportional rate limiting or temporary source controls and monitor for follow-on exploitation attempts against discovered routes.
  4. Review authentication and exposure policy for routes that returned content to unauthenticated requests; restrict administrative, diagnostic, or metadata endpoints as appropriate.
  5. Preserve the cited HTTP evidence and correlate the incident window with workload telemetry if process and flow evidence later becomes available.