OK
reachable
Chrome 113 Linux on /dashboard/partia... - caught by No cookies maintained across multiple requests, No referrer on subsequent request, IP appears normal: 85.11.167.xxx
| Mode | Observations | Maturity | Shift from baseline | Last seen |
|---|---|---|---|---|
| bot-raw | 5564 | 5564 | 0.13 (priority, header order hash, sec ch ua platform) | 12:14:50 |
| signalr-negotiate | 502 | 502 | 0.20 (header order hash, header case pattern, accept encoding ordered) | 12:11:54 |
| navigation | 1602 | 1602 | 0.38 (sec ch ua brands ordered, accept, priority) | 03:48:08 |
| sub-resource | 530 | 530 | 0.30 (priority, header order hash, accept) | 14:43:58 |
| # | Path |
|---|---|
| 1 | /dashboard/partials/topbots |
| 2 | /dashboard/signature/84L6J8Dap2JT5vWdWqekEw |
| 3 | /dashboard/entity/bd1846b7e37142af |
| 4 | /dashboard/signature/LpRnth8B7nYXWFdirHK6XA |
| 5 | /dashboard/entity/fe69e09c053b44d0 |
| 6 | /_content/Mostlylucid.BotDetection.UI/vendor/js/signalr.min.js |
| 7 | /bx bx-help-circle text-sm |
| 8 | /dashboard/signature/eHCJ8Lb7-2yfqeSqVf6dGw |
| 9 | /dashboard/entity/00060d85e23f4de6 |
| 10 | /Probe. Probes endpoints looking for vulns, leaked secrets, or open admin paths. Threat severity is in the shield column. |
| 11 | / |
| 12 | /docs/configuration |
| 13 | /dashboard/signature/mEvve1NRz96O-ZpPNQ2EiQ |
| 14 | /dashboard/entity/a60277abb359440b |
| 15 | /dashboard/signature/W1KU37M-PUcahyFEfWq-9Q |
| 16 | /dashboard/entity/d82c87ab55934d1b |
| 17 | /dashboard/signature/DvXoVWj7FM6ahf806CibLA |
| 18 | /dashboard/signature/-sNGoJdN7QuerkEFkCJIgg |
| 19 | /dashboard/signature/hJnkezZ4xEk2awCbDJhhnQ |
| 20 | /dashboard/entity/0f85f3d5b6124c33 |
| 21 | /bx bxs-help-circle text-lg |
| 22 | /dashboard/signature/FrYjTxo_02cpGb1AM4MTHA |
| 23 | /dashboard/entity/e37f4bb550874fc0 |
| Time | Method | Path | Status | Prob | Conf | Risk Profile | Action | Time |
|---|---|---|---|---|---|---|---|---|
| 02:19:19 | GET | /dashboard/partials/topbots | 400 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.4ms |
| 02:19:00 | GET | /dashboard/signature/84L6J8Dap2JT5vWdWqekEw | 200 | 88 % | 68 % | VeryHigh | Silent Throttle | 11.3ms |
| 02:18:57 | GET | /dashboard/entity/bd1846b7e37142af | 302 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.7ms |
| 02:18:52 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.2ms |
| 02:18:34 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.6ms |
| 02:18:14 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 10.6ms |
| 02:17:52 | GET | /dashboard/signature/LpRnth8B7nYXWFdirHK6XA | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.3ms |
| 02:17:49 | GET | /dashboard/entity/fe69e09c053b44d0 | 302 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.2ms |
| 02:17:45 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.9ms |
| 02:17:35 | GET | /_content/Mostlylucid.BotDetection.UI/vendor/js/signalr.min.js | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.5ms |
| 02:17:21 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.5ms |
| 02:16:54 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 12.1ms |
| 02:16:20 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.8ms |
| 02:16:16 | GET | /bx bx-help-circle text-sm | 404 | 90 % | 68 % | VeryHigh | Silent Throttle | 15.0ms |
| 02:16:09 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 13.3ms |
| 02:15:08 | GET | /dashboard/signature/eHCJ8Lb7-2yfqeSqVf6dGw | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.8ms |
| 02:15:06 | GET | /dashboard/entity/00060d85e23f4de6 | 302 | 90 % | 68 % | VeryHigh | Silent Throttle | 12.0ms |
| 02:14:57 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.6ms |
| 02:14:43 | GET | /Probe. Probes endpoints looking for vulns, leaked secrets, or open admin paths. Threat severity is in the shield column. | 404 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.0ms |
| 02:14:37 | GET | / | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 35.8ms |
| 01:44:54 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.9ms |
| 01:44:37 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.9ms |
| 01:44:33 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.5ms |
| 01:44:30 | GET | /docs/configuration | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.5ms |
| 01:44:03 | GET | /dashboard/signature/mEvve1NRz96O-ZpPNQ2EiQ | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.3ms |
| 01:44:00 | GET | /dashboard/entity/a60277abb359440b | 302 | 90 % | 68 % | VeryHigh | Silent Throttle | 10.9ms |
| 01:43:32 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.8ms |
| 01:38:49 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.6ms |
| 01:38:33 | GET | /Probe. Probes endpoints looking for vulns, leaked secrets, or open admin paths. Threat severity is in the shield column. | 404 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.4ms |
| 01:38:28 | GET | /dashboard/signature/W1KU37M-PUcahyFEfWq-9Q | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 12.4ms |
| 01:38:27 | GET | /dashboard/entity/d82c87ab55934d1b | 302 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.4ms |
| 01:38:22 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 12.7ms |
| 01:37:52 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 12.3ms |
| 01:37:48 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 13.0ms |
| 01:37:43 | GET | /dashboard/partials/topbots | 200 | 67 % | 68 % | High | Allow | 737.4ms |
| 23:02:23 | GET | /dashboard/signature/DvXoVWj7FM6ahf806CibLA | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 12.4ms |
| 23:02:19 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.9ms |
| 23:01:38 | GET | /dashboard/signature/-sNGoJdN7QuerkEFkCJIgg | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 12.0ms |
| 23:01:23 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.5ms |
| 23:01:18 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.5ms |
| 23:01:15 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.5ms |
| 23:00:54 | GET | /dashboard/signature/hJnkezZ4xEk2awCbDJhhnQ | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.9ms |
| 23:00:51 | GET | /dashboard/entity/0f85f3d5b6124c33 | 302 | 90 % | 68 % | VeryHigh | Silent Throttle | 10.4ms |
| 23:00:46 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.6ms |
| 23:00:34 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.2ms |
| 23:00:30 | GET | /bx bxs-help-circle text-lg | 404 | 90 % | 68 % | VeryHigh | Silent Throttle | 12.5ms |
| 23:00:16 | GET | /dashboard/signature/FrYjTxo_02cpGb1AM4MTHA | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.7ms |
| 23:00:14 | GET | /dashboard/entity/e37f4bb550874fc0 | 302 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.3ms |
| 15:57:07 | GET | /bx bxs-help-circle text-lg | 404 | 90 % | 68 % | VeryHigh | Silent Throttle | 13.1ms |
| 15:57:00 | GET | /dashboard/partials/topbots | 200 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.4ms |
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/113.0.0.0 Safari/537.36
| Detector | Confidence Delta | Timing (ms) |
|---|---|---|
|
HeuristicLate
Heuristic model (late): 90 % bot likelihood (301 features)
|
+0.807 | 0.3 |
|
Heuristic
Heuristic model (early): 74 % bot likelihood (21 features)
|
+0.475 | 0.0 |
|
Behavioral
No referrer on subsequent request; No cookies maintained across multiple requests
|
+0.400 | 0.2 |
|
Ip
IP appears normal: 85.11.167.xxx
|
-0.150 | 0.0 |
|
ThreatIntel
spamhaus-drop malicious (SuspiciousNetworkRange)
|
+0.100 | 0.1 |
|
UserAgent
No bot marker in User-Agent (weak human lean; UA is easily spoofed)
|
-0.050 | 0.6 |
|
TlsFingerprint
Using HTTP instead of HTTPS (uncommon for modern browsers)
|
+0.050 | 0.0 |
|
AI
AI analysis: borderline case, monitoring
|
+0.000 | 10.0 |
|
Header
Missing Accept header; deployment norm is low Accept rate (51 % over 204 samples); Browser UA without Accept-Language; deployment norm is low language rate (28 % over 204 samples)
|
+0.000 | 0.1 |
|
AiScraper
No AI scraper signals detected
|
+0.000 | 0.0 |
|
VerifiedBot
No known bot UA pattern
|
+0.000 | 0.0 |
|
SecurityTool
No security tools detected in User-Agent
|
+0.000 | 0.0 |
|
RequestHydrator
Request signals hydrated to sink
|
+0.000 | 0.0 |
|
Http2Fingerprint
Using HTTP/1.1; environment norm is HTTP/1.1 (25 % HTTP/2 over 91 samples)
|
+0.000 | 0.0 |
|
Http3Fingerprint
Connection uses HTTP/1.1 (not HTTP/3)
|
+0.000 | 0.0 |
|
TcpIpFingerprint
Network fingerprint analysis complete (no anomalies detected)
|
+0.000 | 0.0 |
|
TransportProtocol
Transport protocol analysis complete
|
+0.000 | 0.0 |
|
FastPathReputation
No known patterns in reputation cache
|
+0.000 | 0.0 |
No sessions recorded yet.
Sessions are created when a visitor's activity gap exceeds 30 minutes.
reachable
ASP.NET pack enabled
91e6038ebacb4268a4bab17554356661
0 observations
Span + log activity for this fingerprint, ordered by timestamp.
OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)
Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.
aAZFMyxAdHm8jbvIcuR8vw
|
Processing: 11ms
|
Country: NL
|
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/113.0.0.0 Safari/537.36
|
First seen: 2026-07-25 15:57:00 UTC