Back to evidence

Sanitized live incident

Reconnaissance

Native source identity and targetable endpoints are private.

mediumopen
Confidence
92%
First seen
Aug 25, 9:14:41 PM PDT
Evidence through
Aug 25, 10:00:42 PM PDT
AI status
Complete
Likely true positive88% confidence

The incident is most consistent with automated, unauthenticated HTTP surface enumeration against target privatekind. The detector reports 47 requests spanning 42 unique paths, two methods, and eight path categories, with no authenticated requests; the retained HTTP event independently confirms an unauthenticated GET that received a 404. This supports reconnaissance, but not exploit success or compromise. Authorization cannot be determined from the available network evidence, and no process or flow evidence is cited by the incident.

Attack stage
Reconnaissance / HTTP route and method enumeration
Model
gpt-5.6-sol · 5 evidence calls

Observed impact

  • Potential disclosure of the target's reachable HTTP surface and response behavior to the probing source cluster.
  • No observed execution, outbound network consequence, persistence, lateral movement, or data theft is established by the cited evidence.

Deterministic signals

Http.surface enumeration92%

Broad unauthenticated route and HTTP method enumeration observed

335 observations · 1 http

Explicit uncertainty

  • The source key is a traffic/workload cluster and may represent a proxy, NAT gateway, automated scanner, or multiple workers rather than one actor.
  • Network evidence cannot determine whether the enumeration was authorized security testing, benign inventory activity, or unauthorized probing.
  • Only one bounded HTTP event summary was available for direct inspection; the aggregate counts are detector-derived and the exact routes and full method distribution are not exposed.
  • No process or flow event IDs are cited by this incident, so process execution and outbound connection consequences could not be evaluated from those planes.
  • An HTTP 404 does not by itself prove exploit success or failure; no response content indicating command execution was exposed in the bounded summary.

Recommended actions

  1. Validate whether the source cluster and scan window correspond to an approved vulnerability scan, asset inventory, uptime monitor, or penetration test.
  2. Review gateway telemetry for the source cluster over the incident window and confirm that all probed routes and methods were expected.
  3. If unauthorized, apply proportionate rate limiting or temporary source controls and monitor for follow-on authentication attempts or exploit-pattern requests.
  4. Verify that sensitive administrative, diagnostic, and metadata routes require authentication and are not unnecessarily exposed.
  5. Retain relevant HTTP, workload audit, process, and network-flow telemetry for the incident window to support escalation if follow-on activity appears.