Back to evidence

Sanitized live incident

Reconnaissance

Native source identity and targetable endpoints are private.

mediumopen
Confidence
92%
First seen
Aug 25, 7:35:04 PM PDT
Evidence through
Aug 25, 7:58:29 PM PDT
AI status
Complete
Likely true positive93% confidence

The incident is strongly supported as broad HTTP surface reconnaissance against target privatekind. Detector-derived aggregation reports 77 unauthenticated requests spanning 48 paths, two methods, and seven path categories; reviewed samples from the same traffic cluster show rapid probing of distinct root, other, and API-path hashes with mixed 200 and 404 responses. This is consistent with automated route discovery, but authorization and operator intent are not established, so the verdict is likely rather than definitive true positive. The available evidence does not establish exploitation or a downstream workload/network consequence.

Attack stage
Reconnaissance — HTTP route and method enumeration
Model
gpt-5.6-sol · 15 evidence calls

Observed impact

    Deterministic signals

    Http.surface enumeration92%

    Broad unauthenticated route and HTTP method enumeration observed

    312 observations · 12 http

    Explicit uncertainty

    • Authorization and intent are unknown; the behavior could represent an approved scanner, security test, or inventory process.
    • The source key is a traffic/workload cluster and may represent a proxy, NAT gateway, or multiple workers rather than one actor.
    • No process or flow evidence events are cited by this incident, so the bounded process and flow tools could not assess workload execution or outbound-network consequences.
    • HTTP evidence omits exact paths, query strings, headers, and body content; therefore the specific resources targeted and whether any returned content was sensitive cannot be determined.

    Recommended actions

    1. Validate whether the source cluster corresponds to an approved scanner, monitoring service, or scheduled security test.
    2. If unauthorized, apply proportionate gateway rate limiting or temporary source controls and preserve the relevant access logs.
    3. Review the exact server-side access records and application authorization policy for the routes that returned 200 responses to determine whether unintended information was exposed.
    4. Monitor the source cluster and target for follow-on authentication attempts, exploit payloads, unusual process execution, or anomalous outbound flows.