Sanitized live incident
Reconnaissance
Native source identity and targetable endpoints are private.
mediumopen
- Confidence
- 92%
- First seen
- Aug 25, 9:14:41 PM PDT
- Evidence through
- Aug 25, 10:00:42 PM PDT
- AI status
- Complete
Likely true positive88% confidence
The incident is most consistent with automated, unauthenticated HTTP surface enumeration against target privatekind. The detector reports 47 requests spanning 42 unique paths, two methods, and eight path categories, with no authenticated requests; the retained HTTP event independently confirms an unauthenticated GET that received a 404. This supports reconnaissance, but not exploit success or compromise. Authorization cannot be determined from the available network evidence, and no process or flow evidence is cited by the incident.
- Attack stage
- Reconnaissance / HTTP route and method enumeration
- Model
- gpt-5.6-sol · 5 evidence calls
Observed impact
- Potential disclosure of the target's reachable HTTP surface and response behavior to the probing source cluster.
- No observed execution, outbound network consequence, persistence, lateral movement, or data theft is established by the cited evidence.
Deterministic signals
Broad unauthenticated route and HTTP method enumeration observed
335 observations · 1 httpExplicit uncertainty
- The source key is a traffic/workload cluster and may represent a proxy, NAT gateway, automated scanner, or multiple workers rather than one actor.
- Network evidence cannot determine whether the enumeration was authorized security testing, benign inventory activity, or unauthorized probing.
- Only one bounded HTTP event summary was available for direct inspection; the aggregate counts are detector-derived and the exact routes and full method distribution are not exposed.
- No process or flow event IDs are cited by this incident, so process execution and outbound connection consequences could not be evaluated from those planes.
- An HTTP 404 does not by itself prove exploit success or failure; no response content indicating command execution was exposed in the bounded summary.
Recommended actions
- Validate whether the source cluster and scan window correspond to an approved vulnerability scan, asset inventory, uptime monitor, or penetration test.
- Review gateway telemetry for the source cluster over the incident window and confirm that all probed routes and methods were expected.
- If unauthorized, apply proportionate rate limiting or temporary source controls and monitor for follow-on authentication attempts or exploit-pattern requests.
- Verify that sensitive administrative, diagnostic, and metadata routes require authentication and are not unnecessarily exposed.
- Retain relevant HTTP, workload audit, process, and network-flow telemetry for the incident window to support escalation if follow-on activity appears.