You: Bot 100.0% Low
← Dashboard / Signature Detail
IN

Firefox 128 Windows

· Firefox 128.0 / Windows Suspicious
Scraper
Policy: Silent Throttle
Probability
74 %
Confidence
94 %
Risk Profile
High
Threat
None
Hit Count
6
Last Seen
20s ago

Analysis

Firefox 128 Windows on /api/.env - caught by Tier 1 honeypot hit: /api/.env matched */.env*, Request patterns appear normal, IP appears normal: 142.93.208.xxx

Detection Signals

  • Heuristic model (late): 90 % bot likelihood (318 features) 2.01
  • Tier 1 honeypot hit: /api/.env matched */.env* 1.90
  • IP appears normal: 142.93.208.xxx 0.15
  • Headers appear normal 0.15
  • Request patterns appear normal 0.15
  • Client closes connection after each request (bots often avoid persistent connections) 0.06
Network Locale Headers Tool Transport Session Quality
Drifted
Generic Adblocker Firefox (privacy-aware)
Drift vs
44.7%

Fingerprint Profile

TLS Version
Unavailable
HTTP Protocol
HTTP/1.1
Protocol Client
Unavailable
TCP OS Hint
Unavailable
Fingerprint Integrity
Consistent
UA Consistency
Consistent
Headless Indicator
Low
Datacenter IP
Clean

Browser modes same browser, different modes. One row per persisted mode

Mode Observations Maturity Shift from baseline Last seen
bot-raw 1691 1691 0.13 (priority, sec fetch pattern, upgrade insecure requests) 20:02:58
navigation 568 568 0.29 (upgrade insecure requests, accept, dnt) 15:48:43
signalr-negotiate 216 216 0.22 (priority, referer host family, sec fetch pattern) 15:14:00
sub-resource 409 409 0.24 (priority, sec gpc, accept encoding ordered) 13:54:08
websocket-upgrade 13 13 0.31 (ua family, cache control pragma, upgrade insecure requests) 22:54:30
5 modes across 2897 observations. See composite browser-mode fingerprints.
Endpoints Visited (4) Click to expand · stats unavailable
# Path
1 /api/.env
2 /app/.env
3 /env/.env
4 /.env
Raw Requests (6) Click to expand
Time Method Path Status Prob Conf Risk Profile Action Time
17:14:37 GET /api/.env 404 100 % 100 % VeryHigh Silent Throttle 11.5ms
17:14:32 GET /app/.env 404 100 % 100 % VeryHigh Silent Throttle 11.4ms
17:14:27 GET /env/.env 404 100 % 100 % VeryHigh Silent Throttle 11.6ms
17:14:24 GET /.env 404 100 % 100 % VeryHigh Silent Throttle 11.2ms
17:14:07 GET /env/.env 404 100 % 100 % VeryHigh Silent Throttle 12.1ms
17:14:03 GET /.env 404 100 % 100 % VeryHigh Silent Throttle 45.2ms

Bot Probability & Confidence History

StyloBot Detection Overhead (ms)

User Agent

Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0

Detector Contributions (20 detectors)

Detector Confidence Delta Timing (ms)
HeuristicLate
Heuristic model (late): 90 % bot likelihood (318 features)
+0.803 0.3
HoneypotLink
Tier 1 honeypot hit: /api/.env matched */.env*
+0.950 0.1
Ip
IP appears normal: 142.93.208.xxx
-0.150 0.0
Header
Headers appear normal
-0.150 0.0
Behavioral
Request patterns appear normal
-0.150 0.1
TcpIpFingerprint
Client closes connection after each request (bots often avoid persistent connections)
+0.100 0.0
Heuristic
Heuristic model (early): 51 % human likelihood (20 features)
-0.027 0.0
UserAgent
No bot marker in User-Agent (weak human lean; UA is easily spoofed)
-0.050 0.6
Http2Fingerprint
Using HTTP/1.1 instead of HTTP/2 (HTTP/2 rate: 0 % over 8 samples)
+0.050 0.0
TlsFingerprint
Using HTTP instead of HTTPS (uncommon for modern browsers)
+0.050 0.0
AI
AI analysis: borderline case, monitoring
+0.000 10.0
AiScraper
No AI scraper signals detected
+0.000 0.0
VerifiedBot
No known bot UA pattern
+0.000 0.0
SecurityTool
No security tools detected in User-Agent
+0.000 0.0
ContentSequence
Document hit; sequence reset at /api/.env
+0.000 0.1
RequestHydrator
Request signals hydrated to sink
+0.000 0.0
Http3Fingerprint
Connection uses HTTP/1.1 (not HTTP/3)
+0.000 0.0
HeaderCorrelation
Single signature per header profile
+0.000 0.0
TransportProtocol
Transport protocol analysis complete
+0.000 0.0
FastPathReputation
No known patterns in reputation cache
+0.000 0.0

Signal Intelligence

request

protocol HTTP/1.1
accept_encoding gzip, deflate

risk

justification Verified bad bot

Policy applied

Hit history

No sessions recorded yet.

Sessions are created when a visitor's activity gap exceeds 30 minutes.

Effective policy
Loading effective policy…
ASP.NET Pack — Auth health
JWKS health
OK

reachable

Auth pipeline
JWKS reachable
License
Licensed

ASP.NET pack enabled

OTel Mesh — Traces

Fingerprint timeline

87fbf73b769b41959464ad55df07daeb 0 observations

Span + log activity for this fingerprint, ordered by timestamp.

No timeline observations

OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)

Operator actions

Operator actions

Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.

Signature: WPOVcdmiNXgkknH58MzieA | Processing: 11ms | Country: IN | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0 | First seen: 2026-07-25 17:14:03 UTC