OK
reachable
Real browser user (verified) - No header/UA inconsistencies detected, Request patterns appear normal
| Mode | Observations | Maturity | Shift from baseline | Last seen |
|---|---|---|---|---|
| bot-raw | 5119 | 5119 | 0.02 (priority, upgrade insecure requests, cache control pragma) | 06:59:28 |
| navigation | 75 | 75 | 0.34 (cache control pragma, header case pattern, accept) | 15:26:58 |
| signalr-negotiate | 46 | 46 | 0.56 (priority, upgrade insecure requests, cache control pragma) | 18:58:04 |
| sub-resource | 142 | 142 | 0.49 (priority, upgrade insecure requests, cache control pragma) | 18:57:56 |
| websocket-upgrade | 6 | 6 | 0.53 (priority, upgrade insecure requests, header order hash) | 11:36:41 |
| # | Path |
|---|---|
| 1 | /account/login |
| 2 | /dashboard/compliance |
| 3 | /cookies |
| 4 | /dashboard/signature/eKVnpNIpZGW7cFqPt0Uutw |
| 5 | /dashboard/entity/e83d099716b843d1 |
| 6 | /dashboard/site/endpoint |
| 7 | /dashboard/signature/GF5jOXHaSKoQFfNvfVZW_A |
| 8 | /dashboard/entity/8e76dc20818a4ccd |
| 9 | /dashboard/signature/OSDwpoBUAoTUjEdHLMFOXg |
| 10 | /dashboard/entity/c62366010597495b |
| Time | Method | Path | Status | Prob | Conf | Risk Profile | Action | Time |
|---|---|---|---|---|---|---|---|---|
| 05:31:10 | GET | /account/login | 500 | 26 % | 88 % | Low | Allow | 16.8ms |
| 19:00:08 | GET | /dashboard/compliance | 200 | 35 % | 84 % | Low | Allow | 40.9ms |
| 00:45:49 | GET | /cookies | 200 | 34 % | 85 % | Low | Allow | 12.1ms |
| 08:26:26 | GET | /dashboard/signature/eKVnpNIpZGW7cFqPt0Uutw | 200 | 13 % | 68 % | VeryLow | Allow | 12.8ms |
| 08:26:25 | GET | /dashboard/entity/e83d099716b843d1 | 302 | 34 % | 85 % | Low | Allow | 14.4ms |
| 04:31:17 | GET | /dashboard/site/endpoint | 200 | 34 % | 85 % | Low | Allow | 14.9ms |
| 02:14:33 | GET | /dashboard/signature/GF5jOXHaSKoQFfNvfVZW_A | 200 | 13 % | 68 % | VeryLow | Allow | 11.9ms |
| 02:14:31 | GET | /dashboard/entity/8e76dc20818a4ccd | 302 | 34 % | 85 % | Low | Allow | 15.0ms |
| 02:08:20 | GET | /dashboard/signature/OSDwpoBUAoTUjEdHLMFOXg | 200 | 13 % | 68 % | VeryLow | Allow | 12.3ms |
| 02:08:18 | GET | /dashboard/entity/c62366010597495b | 302 | 34 % | 85 % | Low | Allow | 19.9ms |
| 21:31:34 | GET | /account/login | 500 | 21 % | 68 % | Low | Allow | 14.8ms |
| 06:01:28 | GET | /account/login | 200 | 34 % | 85 % | Low | Allow | 12.6ms |
Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
| Detector | Confidence Delta | Timing (ms) |
|---|---|---|
|
Heuristic
Heuristic model (early): 74 % human likelihood (19 features)
|
-0.479 | 0.1 |
|
HeuristicLate
Heuristic model (late): 61 % bot likelihood (303 features)
|
+0.220 | 0.2 |
|
Ip
IP appears normal: 43.159.138.xxx
|
-0.150 | 3.1 |
|
Header
Headers appear normal
|
-0.150 | 0.1 |
|
Behavioral
Request patterns appear normal
|
-0.150 | 0.2 |
|
Inconsistency
No header/UA inconsistencies detected
|
-0.150 | 0.1 |
|
ClaimedIdentity
Safari behavioral profile consistent (score=0.78)
|
-0.150 | 0.1 |
|
VersionAge
Very old OS detected: iOS 13
|
+0.100 | 0.2 |
|
UserAgent
No bot marker in User-Agent (weak human lean; UA is easily spoofed)
|
-0.050 | 0.9 |
|
Http2Fingerprint
Using HTTP/1.1 instead of HTTP/2 (HTTP/2 rate: 40 % over 15 samples)
|
+0.050 | 0.1 |
|
TlsFingerprint
Using HTTP instead of HTTPS (uncommon for modern browsers)
|
+0.050 | 0.0 |
|
AI
AI analysis: borderline case, monitoring
|
+0.000 | 10.3 |
|
Llm
LLM detection disabled or unavailable
|
+0.000 | 0.1 |
|
Intent
Session intent: browsing (threat=0.05, band=None)
|
+0.000 | 0.6 |
|
AiScraper
No AI scraper signals detected
|
+0.000 | 0.1 |
|
Similarity
No prior visitor signatures to compare against yet
|
+0.000 | 0.0 |
|
StreamAbuse
Stream abuse check - non-streaming request
|
+0.000 | 0.0 |
|
VerifiedBot
No known bot UA pattern
|
+0.000 | 0.0 |
|
SecurityTool
No security tools detected in User-Agent
|
+0.000 | 0.1 |
|
CookieBehavior
Too few requests for cookie analysis
|
+0.000 | 0.0 |
|
PiiQueryString
Query string contains PII parameters: token
|
+0.000 | 0.2 |
|
ReputationBias
No learned reputation patterns matched
|
+0.000 | 0.0 |
|
ContentSequence
Document hit; sequence reset at /account/login
|
+0.000 | 0.1 |
|
ProjectHoneypot
Skipped: ProjectHoneypot is disabled in configuration
|
+0.000 | 0.0 |
|
ReactivePattern
No prior error events to analyze
|
+0.000 | 0.0 |
|
RequestHydrator
Request signals hydrated to sink
|
+0.000 | 0.0 |
|
Http3Fingerprint
Connection uses HTTP/1.1 (not HTTP/3)
|
+0.000 | 0.0 |
|
ResponseBehavior
Response coordinator not configured
|
+0.000 | 0.0 |
|
TcpIpFingerprint
Network fingerprint analysis complete (no anomalies detected)
|
+0.000 | 0.1 |
|
HeaderCorrelation
Single signature per header profile
|
+0.000 | 0.0 |
|
TransportProtocol
Transport protocol analysis complete
|
+0.000 | 0.0 |
|
FastPathReputation
No known patterns in reputation cache
|
+0.000 | 0.0 |
|
MultiLayerCorrelation
Cross-signal consistency check complete (not enough data to compare)
|
+0.000 | 0.1 |
No sessions recorded yet.
Sessions are created when a visitor's activity gap exceeds 30 minutes.
reachable
ASP.NET pack enabled
c1f649b6cd2a4bc9bb4630edebd11388
0 observations
Span + log activity for this fingerprint, ordered by timestamp.
OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)
Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.
zKE2kafzl476SDjXTj3PFg
|
Processing: 17ms
|
Country: US
|
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
|
First seen: 2026-07-18 06:01:28 UTC