Back to evidence

Sanitized live incident

Reconnaissance

Native source identity and targetable endpoints are private.

mediumopen
Confidence
92%
First seen
Aug 28, 8:06:06 AM PDT
Evidence through
Aug 28, 8:57:27 AM PDT
AI status
Complete
Likely true positive92% confidence

The bounded HTTP evidence supports the detector's reconnaissance classification: one source cluster sent varied HEAD, GET, and POST requests across root, API, and other route categories on target privatekind during the cited interval [redacted]. Responses varied among 200, 401, 404, 422, and 500, and several GETs returned sizable bodies, indicating that some probed resources responded with content [redacted]. This is strong evidence of surface enumeration, but authorization and operator identity are unknown. No cited process or flow events were available to assess consequences beyond HTTP reconnaissance.

Attack stage
Reconnaissance — web route and HTTP method enumeration
Model
gpt-5.6-sol · 13 evidence calls

Observed impact

  • Potential route and content discovery: multiple GET probes received HTTP 200 with response bodies of 112,594, 33,326, 21,848, 8,525, and 128,022 bytes; the sensitivity of that content is unknown [HTTP [redacted], f

Deterministic signals

Http.surface enumeration92%

Broad unauthenticated route and HTTP method enumeration observed

501 observations · 12 http

Explicit uncertainty

  • The source key is a traffic/workload cluster and cannot establish a unique human, host, or scanning agent identity.
  • Authorization is unknown; the same pattern could come from sanctioned security testing, inventory tooling, or unauthorized reconnaissance.
  • No process-plane or flow-plane evidence references are cited by this incident. Queries using the HTTP event IDs were rejected as not cited, so command execution, outbound consequences, and request-to-process or request-to-socket causality cannot be assessed.
  • Exact paths, query strings, headers, and raw bodies are intentionally excluded from bounded summaries, so the specific resources sought and the sensitivity of returned content are unknown.
  • HTTP response statuses, including 500, do not establish exploit success or failure.

Recommended actions

  1. Confirm whether the source cluster corresponds to an authorized scanner, inventory job, monitoring system, proxy, or NATed workload active during 2026-08-28T15[redacted]06Z–[redacted]53Z.
  2. Review application and gateway logs for the cited request interval, especially the repeated route hash that returned 500 and the endpoints returning sizable 200 responses; determine whether any sensitive metadata or content was exposed.
  3. If the activity is unauthorized, apply proportionate rate limiting or gateway controls and monitor recurrence; avoid treating the source cluster as a guaranteed single identity.
  4. Validate that API authentication and method restrictions are consistently enforced, and minimize unauthenticated route disclosure and verbose error behavior.
  5. Continue monitoring for subsequent authentication attempts, exploit payloads, process execution, or novel outbound flows before escalating to compromise or containment actions.