Back to evidence

Sanitized live incident

Reconnaissance

Native source identity and targetable endpoints are private.

mediumopen
Confidence
92%
First seen
Aug 29, 10:59:59 PM PDT
Evidence through
Aug 30, 12:04:24 AM PDT
AI status
Complete
Likely true positive87% confidence

The evidence supports a real, sustained web-surface enumeration pattern against target privatekind: the detector-derived facts report 1,205 requests over 512 connections, 128 unique paths, four methods, and eight path categories. Verified HTTP samples from the cited cluster show requests to multiple path hashes/categories with mixed 200, 400, 403, and 404 responses, consistent with route probing. This is best assessed as likely true-positive reconnaissance, not confirmed compromise. Authorization and intent remain unresolved, and the incident contains a material semantic inconsistency: its summary calls the activity unauthenticated while its own facts count 1,057 authenticated requests. No process- or flow-plane evidence is cited, so execution, persistence, outbound activity, or other post-reconnaissance consequences are not established.

Attack stage
Reconnaissance / web surface and HTTP method enumeration
Model
gpt-5.6-sol · 7 evidence calls

Observed impact

  • Observed impact is limited to sustained probing of the target's HTTP surface; no post-reconnaissance consequence is established by the cited evidence.
  • At least one cited probe received an HTTP 200 response, indicating some requested resource was served, but status alone does not establish sensitive exposure or exploit success.

Deterministic signals

Http.surface enumeration92%

Broad unauthenticated route and HTTP method enumeration observed

4748 observations · 12 http

Explicit uncertainty

  • Authorization and intent are not established; the activity could be unauthorized reconnaissance, an approved security test, or benign inventory automation.
  • The source key is a traffic/workload cluster and may represent a proxy, NAT gateway, or multiple workers rather than one actor.
  • The signal summary says unauthenticated, while the detector-derived facts count 1,057 authenticated requests; the authentication semantics or aggregation logic cannot be resolved from the bounded evidence.
  • No process or flow evidence references are cited by this incident. Queries using the available HTTP IDs could not retrieve process or flow records, so command execution and outbound network consequences cannot be evaluated.
  • Exact paths, query strings, headers, and bodies are unavailable in the bounded summaries, limiting conclusions about intent and whether successful responses exposed sensitive content.

Recommended actions

  1. Validate the source cluster against approved scanner, inventory, CI/CD, and penetration-testing activity for the incident window.
  2. Review application and gateway logs for the successful and other non-rejected requests, focusing on authentication context, accessed resource sensitivity, and response content without treating status alone as proof of compromise.
  3. If the activity is unauthorized, apply proportionate rate limiting or source controls and monitor for recurrence or transition from enumeration to exploit-oriented requests.
  4. Review the detector's unauthenticated label against its authenticated-request aggregation to correct or document the semantic mismatch.
  5. Do not infer compromise from this incident alone; escalate to containment only if additional application, process, identity, or flow evidence establishes harmful consequences.