You: Bot 100.0% Low
← Dashboard / Signature Detail
DE

Mobile Safari 13 iOS

· Mobile Safari 13.0.3 / iOS Uncertain
Policy: Allow
Probability
30 %
Confidence
92 %
Risk Profile
Elevated
Threat
None
Hit Count
21
Last Seen
37s ago

Analysis

Real browser user (verified) - No header/UA inconsistencies detected, Request patterns appear normal

Detection Signals

  • Heuristic model (early): 74 % human likelihood (19 features) 0.96
  • Heuristic model (late): 61 % bot likelihood (314 features) 0.55
  • IP appears normal: 43.157.46.xxx 0.15
  • Headers appear normal 0.15
  • Request patterns appear normal 0.15
  • No header/UA inconsistencies detected 0.15
Network Locale Headers Tool Transport Session Quality
Closest to
Mobile Safari
Drift vs
34.3%

Fingerprint Profile

TLS Version
Unavailable
HTTP Protocol
HTTP/1.1
Protocol Client
Unavailable
TCP OS Hint
Unavailable
Fingerprint Integrity
Consistent
UA Consistency
Consistent
Headless Indicator
Low
Datacenter IP
Clean

Browser modes same browser, different modes. One row per persisted mode

Mode Observations Maturity Shift from baseline Last seen
bot-raw 5118 5118 0.02 (priority, upgrade insecure requests, cache control pragma) 06:54:19
navigation 75 75 0.34 (cache control pragma, header case pattern, accept) 15:26:58
signalr-negotiate 46 46 0.56 (priority, upgrade insecure requests, cache control pragma) 18:58:04
sub-resource 142 142 0.49 (priority, upgrade insecure requests, cache control pragma) 18:57:56
websocket-upgrade 6 6 0.53 (priority, upgrade insecure requests, header order hash) 11:36:41
5 modes across 5387 observations. See composite browser-mode fingerprints.
Endpoints Visited (17) Click to expand · stats unavailable
# Path
1 /account/login
2 /dashboard/signature/avoYCpy06zcTWwbduHjdpQ
3 /dashboard/entity/5f6b151b5b354535
4 /get-started
5 /dashboard/signature/nrqWwrVf5s01_HJch4KIMA
6 /dashboard/entity/83ae209e96764cfc
7 /dashboard/signature/THdFNGw1-DmeMRZANzENKg
8 /dashboard/entity/cb9e216702c947f0
9 /dashboard/signature/cw9EAU5ol-xOIvWk8JmXgQ
10 /dashboard/entity/8c44d690b8f140ec
11 /dashboard/signature/1UcVRUdxrIQgwe_r99ICLQ
12 /dashboard/entity/c2abe1e5838c4492
13 /dashboard/signature/U-1fKpbfhDFkkFIEkPJvzg
14 /dashboard/entity/31662f56ed024dca
15 /dashboard/otel-mesh/timeline
16 /dashboard/configuration
17 /dashboard/aspnet-pack/routes
Raw Requests (21) Click to expand
Time Method Path Status Prob Conf Risk Profile Action Time
05:29:16 GET /account/login 500 26 % 88 % Low Allow 15.1ms
04:08:43 GET /dashboard/signature/avoYCpy06zcTWwbduHjdpQ 200 13 % 68 % VeryLow Allow 13.1ms
04:08:42 GET /dashboard/entity/5f6b151b5b354535 302 34 % 85 % Low Allow 45.4ms
00:20:03 GET /account/login 500 34 % 85 % Low Allow 88.0ms
22:52:52 GET /get-started 200 26 % 88 % Low Allow 14.4ms
04:31:35 GET /dashboard/signature/nrqWwrVf5s01_HJch4KIMA 200 13 % 68 % VeryLow Allow 13.1ms
04:31:34 GET /dashboard/entity/83ae209e96764cfc 302 34 % 85 % Low Allow 15.5ms
15:00:33 GET /dashboard/signature/THdFNGw1-DmeMRZANzENKg 200 13 % 68 % VeryLow Allow 11.5ms
15:00:33 GET /dashboard/entity/cb9e216702c947f0 302 34 % 85 % Low Allow 15.4ms
11:10:23 GET /dashboard/signature/cw9EAU5ol-xOIvWk8JmXgQ 200 13 % 68 % VeryLow Allow 11.2ms
11:10:20 GET /dashboard/entity/8c44d690b8f140ec 302 34 % 85 % Low Allow 15.1ms
20:11:29 GET /dashboard/signature/1UcVRUdxrIQgwe_r99ICLQ 200 13 % 68 % VeryLow Allow 12.0ms
20:11:28 GET /dashboard/entity/c2abe1e5838c4492 302 34 % 85 % Low Allow 16.2ms
13:18:18 GET /dashboard/signature/U-1fKpbfhDFkkFIEkPJvzg 200 7 % 68 % VeryLow Allow 12.3ms
13:18:14 GET /dashboard/entity/31662f56ed024dca 302 17 % 68 % Low Allow 19.6ms
17:58:07 GET /account/login 500 25 % 88 % Low Allow 23.7ms
14:39:15 GET /account/login 500 34 % 85 % Low Allow 15.2ms
10:13:44 GET /dashboard/otel-mesh/timeline 200 17 % 68 % Low Allow 12.3ms
16:21:55 GET /account/login 200 21 % 68 % Low Allow 12.4ms
06:28:10 GET /dashboard/configuration 200 45 % 81 % Elevated Allow 14.1ms
01:33:00 GET /dashboard/aspnet-pack/routes 200 34 % 85 % Low Allow 13.7ms

Bot Probability & Confidence History

StyloBot Detection Overhead (ms)

User Agent

Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1

Detector Contributions (33 detectors)

Detector Confidence Delta Timing (ms)
Heuristic
Heuristic model (early): 74 % human likelihood (19 features)
-0.479 0.1
HeuristicLate
Heuristic model (late): 61 % bot likelihood (314 features)
+0.220 0.4
Ip
IP appears normal: 43.157.46.xxx
-0.150 1.9
Header
Headers appear normal
-0.150 0.0
Behavioral
Request patterns appear normal
-0.150 0.1
Inconsistency
No header/UA inconsistencies detected
-0.150 0.0
ClaimedIdentity
Safari behavioral profile consistent (score=0.78)
-0.150 0.1
VersionAge
Very old OS detected: iOS 13
+0.100 0.2
UserAgent
No bot marker in User-Agent (weak human lean; UA is easily spoofed)
-0.050 0.7
Http2Fingerprint
Using HTTP/1.1 instead of HTTP/2 (HTTP/2 rate: 42 % over 12 samples)
+0.050 0.0
TlsFingerprint
Using HTTP instead of HTTPS (uncommon for modern browsers)
+0.050 0.0
AI
AI analysis: borderline case, monitoring
+0.000 10.3
Llm
LLM detection disabled or unavailable
+0.000 0.1
Intent
Session intent: browsing (threat=0.05, band=None)
+0.000 0.5
AiScraper
No AI scraper signals detected
+0.000 0.0
Similarity
No prior visitor signatures to compare against yet
+0.000 0.0
StreamAbuse
Stream abuse check - non-streaming request
+0.000 0.0
VerifiedBot
No known bot UA pattern
+0.000 0.0
SecurityTool
No security tools detected in User-Agent
+0.000 0.1
CookieBehavior
Too few requests for cookie analysis
+0.000 0.0
PiiQueryString
Query string contains PII parameters: token
+0.000 0.2
ReputationBias
No learned reputation patterns matched
+0.000 0.0
ContentSequence
Document hit; sequence reset at /account/login
+0.000 0.1
ProjectHoneypot
Skipped: ProjectHoneypot is disabled in configuration
+0.000 0.0
ReactivePattern
No prior error events to analyze
+0.000 0.0
RequestHydrator
Request signals hydrated to sink
+0.000 0.0
Http3Fingerprint
Connection uses HTTP/1.1 (not HTTP/3)
+0.000 0.0
ResponseBehavior
Response coordinator not configured
+0.000 0.0
TcpIpFingerprint
Network fingerprint analysis complete (no anomalies detected)
+0.000 0.0
HeaderCorrelation
Single signature per header profile
+0.000 0.0
TransportProtocol
Transport protocol analysis complete
+0.000 0.0
FastPathReputation
No known patterns in reputation cache
+0.000 0.0
MultiLayerCorrelation
Cross-signal consistency check complete (not enough data to compare)
+0.000 0.1

Signal Intelligence

request

protocol HTTP/1.1
accept_encoding gzip

risk

justification Classified Unknown (probability 0.26, confidence 0.88)
friendly_pin_trace not-applicable:botType=Unknown,yamlType=null,botName=null

Policy applied

Hit history

No sessions recorded yet.

Sessions are created when a visitor's activity gap exceeds 30 minutes.

Effective policy
Loading effective policy…
ASP.NET Pack — Auth health
JWKS health
OK

reachable

Auth pipeline
JWKS reachable
License
Licensed

ASP.NET pack enabled

OTel Mesh — Traces

Fingerprint timeline

c1f649b6cd2a4bc9bb4630edebd11388 0 observations

Span + log activity for this fingerprint, ordered by timestamp.

No timeline observations

OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)

Operator actions

Operator actions

Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.

Signature: yoqWglqps-YERqXL0-kVpw | Processing: 15ms | Country: DE | UA: Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1 | First seen: 2026-07-17 01:33:00 UTC