You: Bot 100.0% Low
← Dashboard / Signature Detail
US

Mobile Safari 13 iOS

· Mobile Safari 13.0.3 / iOS Human
Policy: Allow
Probability
28 %
Confidence
93 %
Risk Profile
Elevated
Threat
None
Hit Count
15
Last Seen
44s ago

Analysis

Real browser user (likely) - Request patterns appear normal, IP appears normal: 170.106.140.xxx

Detection Signals

  • Heuristic model (early): 79 % human likelihood (19 features) 1.17
  • Heuristic model (late): 55 % bot likelihood (294 features) 0.27
  • IP appears normal: 170.106.140.xxx 0.15
  • Headers appear normal 0.15
  • Request patterns appear normal 0.15
  • TLS connection appears normal 0.15
Network Locale Headers Tool Transport Session Quality
Closest to
Mobile Safari
Drift vs
34.2%

Fingerprint Profile

TLS Version
TLSv1.3
HTTP Protocol
HTTP/2
Protocol Client
TLS_AES_256_GCM_SHA384
TCP OS Hint
Unavailable
Fingerprint Integrity
Suspect
UA Consistency
Consistent
Headless Indicator
Low
Datacenter IP
Clean

Browser modes same browser, different modes. One row per persisted mode

Mode Observations Maturity Shift from baseline Last seen
bot-raw 4769 4769 0.02 (priority, upgrade insecure requests, cache control pragma) 17:57:00
navigation 75 75 0.34 (cache control pragma, header case pattern, accept) 15:26:58
signalr-negotiate 46 46 0.56 (priority, upgrade insecure requests, cache control pragma) 18:58:04
sub-resource 142 142 0.49 (priority, upgrade insecure requests, cache control pragma) 18:57:56
websocket-upgrade 6 6 0.53 (priority, upgrade insecure requests, header order hash) 11:36:41
5 modes across 5038 observations. See composite browser-mode fingerprints.
Endpoints Visited (12) Click to expand · stats unavailable
# Path
1 /refund
2 /dashboard/traffic
3 /dashboard/activity
4 /dashboard
5 /dashboard/signature/FtVdh6JsFcz5q7z_eAiYZQ
6 /dashboard/entity/5e4e699d243040f7
7 /account/login
8 /dashboard/signature/VAGJrHJDUQgP8C_ewWp2OA
9 /dashboard/entity/284630185dc045bb
10 /dashboard/signature/hFb7F_t_usr6ziOQA9wxGA
11 /dashboard/entity/e582c595de624a0c
12 /fingerprint/headless-chrome
Raw Requests (15) Click to expand
Time Method Path Status Prob Conf Risk Profile Action Time
17:02:46 GET /refund 200 18 % 68 % Low Allow 12.7ms
18:11:51 GET /dashboard/traffic 400 13 % 68 % VeryLow Allow 12.5ms
18:11:45 GET /dashboard/activity 301 13 % 68 % VeryLow Allow 11.8ms
18:11:41 GET /dashboard 301 34 % 85 % Low Allow 14.2ms
06:06:30 GET /dashboard/signature/FtVdh6JsFcz5q7z_eAiYZQ 200 9 % 68 % VeryLow Allow 11.6ms
06:06:27 GET /dashboard/entity/5e4e699d243040f7 302 21 % 68 % Low Allow 13.9ms
03:53:42 GET /account/login 500 34 % 85 % Low Allow 71.8ms
00:13:14 GET /account/login 500 35 % 84 % Low Allow 14.2ms
14:05:39 GET /dashboard/signature/VAGJrHJDUQgP8C_ewWp2OA 200 13 % 68 % VeryLow Allow 11.7ms
14:05:38 GET /dashboard/entity/284630185dc045bb 302 34 % 85 % Low Allow 15.9ms
01:26:29 GET /dashboard/signature/hFb7F_t_usr6ziOQA9wxGA 200 13 % 68 % VeryLow Allow 12.5ms
01:26:27 GET /dashboard/entity/e582c595de624a0c 302 34 % 85 % Low Allow 13.2ms
23:11:10 GET /account/login 500 21 % 68 % Low Allow 14.4ms
13:32:15 GET /account/login 200 21 % 68 % Low Allow 12.4ms
19:41:10 GET /fingerprint/headless-chrome 200 21 % 68 % Low Allow 12.0ms

Bot Probability & Confidence History

StyloBot Detection Overhead (ms)

User Agent

Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1

Detector Contributions (19 detectors)

Detector Confidence Delta Timing (ms)
Heuristic
Heuristic model (early): 79 % human likelihood (19 features)
-0.583 0.1
HeuristicLate
Heuristic model (late): 55 % bot likelihood (294 features)
+0.109 0.2
Ip
IP appears normal: 170.106.140.xxx
-0.150 1.3
Header
Headers appear normal
-0.150 0.0
Behavioral
Request patterns appear normal
-0.150 0.1
TlsFingerprint
TLS connection appears normal
-0.150 0.0
UserAgent
No bot marker in User-Agent (weak human lean; UA is easily spoofed)
-0.050 0.6
Http2Fingerprint
No HTTP/2 stream priority (browsers typically use this)
+0.050 0.0
AI
AI analysis: borderline case, monitoring
+0.000 10.1
AiScraper
No AI scraper signals detected
+0.000 0.0
VerifiedBot
No known bot UA pattern
+0.000 0.0
SecurityTool
No security tools detected in User-Agent
+0.000 0.0
ContentSequence
Document hit; sequence reset at /refund
+0.000 0.1
RequestHydrator
Request signals hydrated to sink
+0.000 0.0
Http3Fingerprint
Connection uses HTTP/2 (not HTTP/3)
+0.000 0.0
TcpIpFingerprint
Network fingerprint analysis complete (no anomalies detected)
+0.000 0.0
HeaderCorrelation
Single signature per header profile
+0.000 0.0
TransportProtocol
Transport protocol analysis complete
+0.000 0.0
FastPathReputation
No known patterns in reputation cache
+0.000 0.0

Signal Intelligence

h2

protocol h2

request

protocol HTTP/2
accept_encoding gzip, br

risk

justification Classified Unknown (probability 0.18, confidence 0.68)
friendly_pin_trace not-applicable:botType=Unknown,yamlType=null,botName=null

tls

cipher TLS_AES_256_GCM_SHA384
Version TLSv1.3
version TLSv1.3

Policy applied

Hit history

No sessions recorded yet.

Sessions are created when a visitor's activity gap exceeds 30 minutes.

Effective policy
Loading effective policy…
ASP.NET Pack — Auth health
JWKS health
OK

reachable

Auth pipeline
JWKS reachable
License
Licensed

ASP.NET pack enabled

OTel Mesh — Traces

Fingerprint timeline

c1f649b6cd2a4bc9bb4630edebd11388 0 observations

Span + log activity for this fingerprint, ordered by timestamp.

No timeline observations

OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)

Operator actions

Operator actions

Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.

Signature: Pn_OdDqpI9c30ocxGLYGuQ | Processing: 13ms | Country: US | UA: Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1 | First seen: 2026-07-16 19:41:10 UTC