Back to evidence

Sanitized live incident

Reconnaissance

Native source identity and targetable endpoints are private.

mediumopen
Confidence
92%
First seen
Aug 30, 10:27:13 PM PDT
Evidence through
Aug 30, 10:44:16 PM PDT
AI status
Complete
Likely true positive89% confidence

The incident is best assessed as likely true-positive application-surface reconnaissance. The detector aggregated 64 requests from one traffic/workload cluster across 51 unique paths, five HTTP methods, and six path categories, with 53 rejected responses. The verified samples show rapid requests to distinct route hashes, mixed GET/POST usage, and repeated 401/422 responses, consistent with automated route and method enumeration. Two sampled requests returned HTTP 200, but status alone does not establish exploitation or compromise. Authorization is unknown, so sanctioned security testing or inventory remains a plausible alternative. No process or flow evidence is cited by this incident, so no execution, outbound consequence, persistence, lateral movement, or data loss is established.

Attack stage
Reconnaissance — application route and HTTP method enumeration
Model
gpt-5.6-sol · 8 evidence calls

Observed impact

  • Observed impact is limited to probing and potential mapping of the application's exposed routes and method behavior; no post-exploitation consequence is established.

Deterministic signals

Http.surface enumeration92%

Broad unauthenticated route and HTTP method enumeration observed

173 observations · 2 http

Explicit uncertainty

  • The source key identifies a traffic/workload cluster, not a proven person or single agent; it may represent a proxy, NAT gateway, or multiple workers.
  • Authorization is not established. The same pattern could arise from sanctioned security testing, health/inventory automation, or unauthorized reconnaissance.
  • The incident cites only HTTP evidence. Process and flow evidence could not be retrieved from the incident's cited event set, so downstream execution or network consequences cannot be evaluated; this is not proof that none occurred.
  • Exact paths, headers, query strings, and body contents are excluded from the bounded summaries, so route sensitivity, request intent, and the meaning of the HTTP 200 response bodies cannot be determined.
  • The aggregate reports one authenticated request, but the available summaries do not identify which sampled event it was or whether the authentication was legitimate.

Recommended actions

  1. Confirm whether the source cluster and time window correspond to an approved scanner, penetration test, inventory job, or deployment validation.
  2. Review the application and identity audit records for the single authenticated request and the two sampled HTTP 200 responses, focusing on authorization context and any state-changing action; do not infer success from status alone.
  3. If the activity is unauthorized, apply proportionate gateway rate limits or temporary source controls and monitor for follow-on exploit attempts against the discovered routes.
  4. Review exposure and authentication requirements for the enumerated route categories, and ensure rejected responses do not reveal unnecessary route or method details.
  5. Preserve the cited HTTP records and correlate them with workload telemetry using an independently reliable request identifier if available.