Sanitized live incident
Reconnaissance
Native source identity and targetable endpoints are private.
- Confidence
- 92%
- First seen
- Aug 30, 12:13:16 PM PDT
- Evidence through
- Aug 30, 12:13:28 PM PDT
- AI status
- Complete
Likely true positive for automated HTTP reconnaissance against target privatekind. The cited HTTP sequence supports rapid, broad, unauthenticated surface enumeration: the detector aggregated 64 requests to 64 unique paths across two methods and seven path categories in roughly 2.74 seconds, with 52 rejected responses. Verified examples have distinct path hashes, complete captures, empty request bodies, and mostly uniform 404 responses; the root request returned 200. This establishes probing behavior, not exploit success. Authorization is unknown, and no process or flow evidence is cited by the incident, so no workload compromise or follow-on network consequence is established.
- Attack stage
- Reconnaissance / discovery: HTTP route and method enumeration
- Model
- gpt-5.6-sol · 8 evidence calls
Observed impact
- Observed impact is limited to unauthenticated HTTP surface probing and receipt of server responses; no execution, persistence, lateral movement, egress consequence, or data theft is established by the available cited evidence.
Deterministic signals
Broad unauthenticated route and HTTP method enumeration observed
266 observations · 12 httpExplicit uncertainty
- The source_key is a derived traffic/workload cluster, not a verified human or scanner identity; it may represent a proxy, NAT gateway, or multiple workers.
- Network evidence does not establish whether this enumeration was authorized security testing, inventory activity, or hostile reconnaissance.
- The incident cites only HTTP-plane events. Process- and flow-evidence retrieval could not resolve the HTTP event IDs as cited process/flow events, so workload execution and outbound-flow consequences cannot be assessed from this incident.
- Exact paths, query strings, headers, and response contents are intentionally excluded from bounded summaries, so the specific resources sought and any information disclosed by successful responses are unknown.
- Only representative HTTP records are individually exposed while request count and breadth are detector aggregates; the exact second method and full response distribution are not visible in the bounded summaries.
Recommended actions
- Verify whether the source cluster and scan window correspond to an approved vulnerability scan, synthetic monitor, or asset-inventory job.
- Review adjacent gateway/application telemetry for follow-on requests from the same source cluster, especially authentication attempts, exploit payload indicators, or unusual successful responses.
- Validate that only intended public routes are reachable and that error responses do not disclose route, framework, or deployment details.
- Apply proportionate per-source or per-connection rate limits for broad unauthenticated path enumeration if this activity is unauthorized and operationally safe to constrain.
- Retain and correlate the cited HTTP evidence; escalate containment only if follow-on execution, suspicious egress, credential use, or other compromise evidence appears.