You: Bot 100.0% Low
← Dashboard / Signature Detail
NL

Chrome 147 Windows

· Chrome 147.0.0 / Windows Suspicious
Unknown
Policy: Silent Throttle
Probability
66 %
Confidence
94 %
Risk Profile
High
Threat
None
Hit Count
25
Last Seen
57s ago

Analysis

Chrome 147 Windows on /dist/assets/inde... - caught by Request patterns appear normal, IP appears normal: 94.154.43.xxx, TLS connection appears normal

Detection Signals

  • Heuristic model (late): 97 % bot likelihood (302 features) 2.34
  • Heuristic model (early): 78 % bot likelihood (22 features) 1.12
  • IP appears normal: 94.154.43.xxx 0.15
  • Request patterns appear normal 0.15
  • TLS connection appears normal 0.15
  • Client closes connection after each request (bots often avoid persistent connections) 0.06
Network Locale Headers Tool Transport Session Quality
Closest to
Chrome Desktop
Drift vs
32.1%

Fingerprint Profile

TLS Version
TLSv1.3
HTTP Protocol
HTTP/1.1
Protocol Client
TLS_AES_256_GCM_SHA384
TCP OS Hint
Unavailable
Fingerprint Integrity
Suspect
UA Consistency
Consistent
Headless Indicator
Low
Datacenter IP
Clean

Browser modes same browser, different modes. One row per persisted mode

Mode Observations Maturity Shift from baseline Last seen
signalr-negotiate 500 500 0.20 (header order hash, header case pattern, accept encoding ordered) 10:12:13
bot-raw 5534 5534 0.13 (priority, header order hash, sec ch ua platform) 10:03:41
navigation 1602 1602 0.38 (sec ch ua brands ordered, accept, priority) 03:48:08
sub-resource 530 530 0.30 (priority, header order hash, accept) 14:43:58
4 modes across 8166 observations. See composite browser-mode fingerprints.
Endpoints Visited (4) Click to expand · stats unavailable
# Path
1 /dist/assets/index.js
2 /.env
3 /
4 /resources/fbczt/admin/keycloak.v2/assets/main-zvz9g12o.js
Raw Requests (25) Click to expand
Time Method Path Status Prob Conf Risk Profile Action Time
23:20:12 GET /dist/assets/index.js 200 90 % 68 % VeryHigh Silent Throttle 12.7ms
22:41:47 GET /dist/assets/index.js 200 90 % 68 % VeryHigh Silent Throttle 22.0ms
10:15:03 GET /.env 404 100 % 100 % VeryHigh Silent Throttle 13.9ms
09:56:09 GET / 200 90 % 68 % VeryHigh Silent Throttle 12.9ms
07:38:40 GET / 200 90 % 68 % VeryHigh Silent Throttle 13.7ms
05:59:50 GET /.env 404 100 % 100 % VeryHigh Silent Throttle 13.0ms
16:09:51 GET /dist/assets/index.js 200 90 % 68 % VeryHigh Silent Throttle 12.6ms
03:36:56 GET /.env 404 100 % 100 % VeryHigh Silent Throttle 14.0ms
03:25:14 GET /.env 404 100 % 100 % VeryHigh Silent Throttle 12.4ms
03:25:13 GET /.env 404 100 % 100 % VeryHigh Silent Throttle 11.2ms
03:25:13 GET /.env 404 100 % 100 % VeryHigh Silent Throttle 13.0ms
17:32:35 GET /resources/fbczt/admin/keycloak.v2/assets/main-zvz9g12o.js 200 90 % 68 % VeryHigh Silent Throttle 11.9ms
17:32:32 GET /dist/assets/index.js 200 90 % 68 % VeryHigh Silent Throttle 14.0ms
13:49:24 GET /dist/assets/index.js 304 90 % 68 % VeryHigh Silent Throttle 13.8ms
06:49:49 GET / 200 90 % 68 % VeryHigh Silent Throttle 22.0ms
02:06:48 GET / 200 90 % 68 % VeryHigh Silent Throttle 14.0ms
00:13:52 GET /.env 404 100 % 100 % VeryHigh Silent Throttle 20.5ms
18:07:06 GET /dist/assets/index.js 200 90 % 68 % VeryHigh Silent Throttle 11.6ms
18:07:04 GET /resources/fbczt/admin/keycloak.v2/assets/main-zvz9g12o.js 200 90 % 68 % VeryHigh Silent Throttle 11.8ms
05:54:44 GET /.env 200 100 % 100 % VeryHigh Silent Throttle 49.4ms
05:54:43 GET /.env 200 100 % 100 % VeryHigh Silent Throttle 39.4ms
03:56:34 GET /.env 200 100 % 100 % VeryHigh Silent Throttle 12.5ms
01:44:02 GET /.env 200 100 % 100 % VeryHigh Silent Throttle 12.2ms
21:37:43 GET / 200 90 % 68 % VeryHigh Silent Throttle 11.9ms
20:54:54 GET /.env 200 100 % 100 % VeryHigh Silent Throttle 12.6ms

Bot Probability & Confidence History

StyloBot Detection Overhead (ms)

User Agent

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36

Detector Contributions (18 detectors)

Detector Confidence Delta Timing (ms)
HeuristicLate
Heuristic model (late): 97 % bot likelihood (302 features)
+0.934 0.3
Heuristic
Heuristic model (early): 78 % bot likelihood (22 features)
+0.558 0.1
Ip
IP appears normal: 94.154.43.xxx
-0.150 1.3
Behavioral
Request patterns appear normal
-0.150 0.1
TlsFingerprint
TLS connection appears normal
-0.150 0.0
TcpIpFingerprint
Client closes connection after each request (bots often avoid persistent connections)
+0.100 0.0
UserAgent
No bot marker in User-Agent (weak human lean; UA is easily spoofed)
-0.050 0.4
Http2Fingerprint
Using HTTP/1.1 instead of HTTP/2 (HTTP/2 rate: 88 % over 405 samples)
+0.088 0.0
AI
AI analysis: borderline case, monitoring
+0.000 10.3
Header
Browser UA without Accept-Language; deployment norm is low language rate (48 % over 326 samples)
+0.000 0.1
AiScraper
No AI scraper signals detected
+0.000 0.0
VerifiedBot
No known bot UA pattern
+0.000 0.0
SecurityTool
No security tools detected in User-Agent
+0.000 0.0
RequestHydrator
Request signals hydrated to sink
+0.000 0.0
Http3Fingerprint
Connection uses HTTP/1.1 (not HTTP/3)
+0.000 0.0
HeaderCorrelation
Single signature per header profile
+0.000 0.0
TransportProtocol
Transport protocol analysis complete
+0.000 0.0
FastPathReputation
No known patterns in reputation cache
+0.000 0.0

Signal Intelligence

request

protocol HTTP/1.1
accept_encoding identity

risk

justification Classified Unknown (probability 0.90, confidence 0.68)
friendly_pin_trace not-applicable:botType=Unknown,yamlType=null,botName=null

tls

cipher TLS_AES_256_GCM_SHA384
Version TLSv1.3
version TLSv1.3

Policy applied

Hit history

No sessions recorded yet.

Sessions are created when a visitor's activity gap exceeds 30 minutes.

Effective policy
Loading effective policy…
ASP.NET Pack — Auth health
JWKS health
OK

reachable

Auth pipeline
JWKS reachable
License
Licensed

ASP.NET pack enabled

OTel Mesh — Traces

Fingerprint timeline

91e6038ebacb4268a4bab17554356661 0 observations

Span + log activity for this fingerprint, ordered by timestamp.

No timeline observations

OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)

Operator actions

Operator actions

Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.

Signature: p32DhdL-bQ9X4kxj-ASrYA | Processing: 13ms | Country: NL | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 | First seen: 2026-07-16 20:54:54 UTC