You: Bot 100.0% Low
← Dashboard / Signature Detail
US

Applebot

· Applebot 0.1 / macOS Bot
SearchEngine
Policy: Allow
Probability
96 %
Confidence
91 %
Risk Profile
VeryHigh
Threat
None
Hit Count
8
Last Seen
18s ago

Analysis

Applebot on /robots.txt - caught by Known bot pattern: Applebot, Highly repetitive: /robots.txt→/robots.txt (p=100 %), Request patterns appear normal

Detection Signals

  • Heuristic model (late): 98 % bot likelihood (325 features) 2.40
  • Known bot pattern: Applebot 1.35
  • Heuristic model (early): 78 % bot likelihood (22 features) 1.14
  • Request patterns appear normal; Highly repetitive: /robots.txt→/robots.txt (p=100 %) 0.33
  • IP appears normal: 17.246.23.xxx 0.15
  • TLS connection appears normal 0.15
Network Locale Headers Tool Transport Session Quality
Drift vs
56.5%

Fingerprint Profile

TLS Version
TLSv1.3
HTTP Protocol
HTTP/2
Protocol Client
TLS_AES_256_GCM_SHA384
TCP OS Hint
Unavailable
Fingerprint Integrity
Suspect
UA Consistency
Flagged
Headless Indicator
Low
Datacenter IP
Clean

Browser modes same browser, different modes. One row per persisted mode

Mode Observations Maturity Shift from baseline Last seen
bot-raw 9084 9084 0.04 (ua family, header case pattern, referer host family) 11:04:22
sub-resource 795 795 0.40 (ua family, header case pattern, referer host family) 10:29:59
signalr-negotiate 179 179 0.39 (ua family, header order hash, referer host family) 10:26:36
websocket-upgrade 10 10 0.40 (x requested with, header case pattern, header order hash) 20:32:09
navigation 14 14 0.46 (upgrade insecure requests, custom header signature, header order hash) 12:11:32
5 modes across 10082 observations. See composite browser-mode fingerprints.
Endpoints Visited (2) Click to expand · stats unavailable
# Path
1 /robots.txt
2 /realms/stylobot/protocol/openid-connect/auth
Raw Requests (8) Click to expand
Time Method Path Status Prob Conf Risk Profile Action Time
18:14:11 GET /robots.txt 404 100 % 100 % VeryLow Allow 11.9ms
18:14:10 GET /robots.txt 404 100 % 100 % VeryLow Allow 12.0ms
18:14:08 GET /robots.txt 404 100 % 100 % VeryLow Allow 11.6ms
18:14:07 GET /robots.txt 404 100 % 100 % VeryLow Allow 12.4ms
18:14:05 GET /robots.txt 404 100 % 100 % VeryLow Allow 12.0ms
18:14:04 GET /robots.txt 404 100 % 100 % VeryLow Allow 12.0ms
18:14:02 GET /robots.txt 404 100 % 100 % VeryLow Allow 11.8ms
18:14:02 GET /realms/stylobot/protocol/openid-connect/auth 200 100 % 100 % VeryLow Allow 63.0ms

Bot Probability & Confidence History

StyloBot Detection Overhead (ms)

User Agent

Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)

Detector Contributions (19 detectors)

Detector Confidence Delta Timing (ms)
HeuristicLate
Heuristic model (late): 98 % bot likelihood (325 features)
+0.961 0.4
UserAgent
Known bot pattern: Applebot
+0.900 0.5
Heuristic
Heuristic model (early): 78 % bot likelihood (22 features)
+0.568 0.1
Behavioral
Request patterns appear normal; Highly repetitive: /robots.txt→/robots.txt (p=100 %)
+0.250 0.3
Ip
IP appears normal: 17.246.23.xxx
-0.150 0.0
TlsFingerprint
TLS connection appears normal
-0.150 0.0
AI
AI analysis: borderline case, monitoring
+0.000 9.9
Header
Browser UA without Accept-Language; deployment norm is low language rate (48 % over 288 samples)
+0.000 0.1
AiScraper
No AI scraper signals detected
+0.000 0.1
VerifiedBot
Verified Applebot via fcrdns
+0.000 0.2
SecurityTool
No security tools detected in User-Agent
+0.000 0.1
ContentSequence
Document hit; sequence reset at /robots.txt
+0.000 0.1
RequestHydrator
Request signals hydrated to sink
+0.000 0.0
Http2Fingerprint
HTTP/2 analysis complete (no anomalies detected)
+0.000 0.0
Http3Fingerprint
Connection uses HTTP/2 (not HTTP/3)
+0.000 0.0
TcpIpFingerprint
Network fingerprint analysis complete (no anomalies detected)
+0.000 0.0
HeaderCorrelation
Single signature per header profile
+0.000 0.0
TransportProtocol
Transport protocol analysis complete
+0.000 0.0
FastPathReputation
No known patterns in reputation cache
+0.000 0.1

Signal Intelligence

h2

protocol h2

request

protocol HTTP/2
accept_encoding gzip,identity

risk

justification Cryptographically verified good bot

tls

cipher TLS_AES_256_GCM_SHA384
Version TLSv1.3
version TLSv1.3

Policy applied

Hit history

No sessions recorded yet.

Sessions are created when a visitor's activity gap exceeds 30 minutes.

Effective policy
Loading effective policy…
ASP.NET Pack — Auth health
JWKS health
OK

reachable

Auth pipeline
JWKS reachable
License
Licensed

ASP.NET pack enabled

OTel Mesh — Traces

Fingerprint timeline

32bb80482ffb48089559f74451ecff49 0 observations

Span + log activity for this fingerprint, ordered by timestamp.

No timeline observations

OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)

Operator actions

Operator actions

Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.

Signature: zvyQ8Ze39b911vdaWco3FQ | Processing: 12ms | Country: US | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot) | First seen: 2026-07-21 18:14:02 UTC