You: Bot 100.0% Low
← Dashboard / Signature Detail
GB

Edge 122 Windows

· Edge 122.0.0 / Windows Suspicious
Unknown
Policy: Silent Throttle
Probability
52 %
Confidence
91 %
Risk Profile
Medium
Threat
None
Hit Count
1
Last Seen
56s ago

Analysis

Edge 122 Windows on /favicon.ico - caught by Request patterns appear normal, IP appears normal: 198.244.133.xxx, TLS connection appears normal

Detection Signals

  • Heuristic model (late): 95 % bot likelihood (300 features) 2.24
  • Heuristic model (early): 72 % bot likelihood (22 features) 0.90
  • IP appears normal: 198.244.133.xxx 0.15
  • Request patterns appear normal 0.15
  • TLS connection appears normal 0.15
  • Missing connection reuse header (unusual for real browsers) 0.14
Network Locale Headers Tool Transport Session Quality
Drift vs
44.8%

Fingerprint Profile

TLS Version
TLSv1.3
HTTP Protocol
HTTP/2
Protocol Client
TLS_AES_256_GCM_SHA384
TCP OS Hint
Unavailable
Fingerprint Integrity
Suspect
UA Consistency
Consistent
Headless Indicator
Low
Datacenter IP
Clean

Browser modes same browser, different modes. One row per persisted mode

Mode Observations Maturity Shift from baseline Last seen
bot-raw 1807 1807 0.12 (priority, sec fetch pattern, upgrade insecure requests) 07:11:15
signalr-negotiate 232 232 0.21 (priority, referer host family, sec fetch pattern) 06:50:16
sub-resource 427 427 0.24 (priority, sec gpc, accept encoding ordered) 06:50:15
navigation 570 570 0.29 (upgrade insecure requests, accept, dnt) 06:50:09
websocket-upgrade 13 13 0.31 (ua family, cache control pragma, upgrade insecure requests) 22:54:30
5 modes across 3049 observations. See composite browser-mode fingerprints.
Endpoints Visited (1) Click to expand · stats unavailable
# Path
1 /favicon.ico
Raw Requests (1) Click to expand
Time Method Path Status Prob Conf Risk Profile Action Time
03:50:24 GET /favicon.ico 200 90 % 68 % VeryHigh Silent Throttle 12.8ms

User Agent

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0

Detector Contributions (18 detectors)

Detector Confidence Delta Timing (ms)
HeuristicLate
Heuristic model (late): 95 % bot likelihood (300 features)
+0.897 0.3
Heuristic
Heuristic model (early): 72 % bot likelihood (22 features)
+0.449 0.1
Ip
IP appears normal: 198.244.133.xxx
-0.150 0.0
Behavioral
Request patterns appear normal
-0.150 0.2
TlsFingerprint
TLS connection appears normal
-0.150 0.0
TcpIpFingerprint
Missing connection reuse header (unusual for real browsers)
+0.200 0.0
UserAgent
No bot marker in User-Agent (weak human lean; UA is easily spoofed)
-0.050 0.6
Http2Fingerprint
No HTTP/2 stream priority (browsers typically use this)
+0.050 0.0
AI
AI analysis: borderline case, monitoring
+0.000 10.9
Header
Browser UA without Accept-Language; deployment norm is low language rate (41 % over 283 samples)
+0.000 0.1
AiScraper
No AI scraper signals detected
+0.000 0.0
VerifiedBot
No known bot UA pattern
+0.000 0.0
SecurityTool
No security tools detected in User-Agent
+0.000 0.1
ContentSequence
Sequence on track at position 1
+0.000 0.4
RequestHydrator
Request signals hydrated to sink
+0.000 0.0
Http3Fingerprint
Connection uses HTTP/2 (not HTTP/3)
+0.000 0.0
TransportProtocol
Transport protocol analysis complete
+0.000 0.0
FastPathReputation
No known patterns in reputation cache
+0.000 0.0

Signal Intelligence

h2

protocol h2

request

protocol HTTP/2

risk

justification Classified Unknown (probability 0.90, confidence 0.68)
friendly_pin_trace not-applicable:botType=Unknown,yamlType=null,botName=null

tls

cipher TLS_AES_256_GCM_SHA384
Version TLSv1.3
version TLSv1.3

Policy applied

Hit history

No sessions recorded yet.

Sessions are created when a visitor's activity gap exceeds 30 minutes.

Effective policy
Loading effective policy…
ASP.NET Pack — Auth health
JWKS health
OK

reachable

Auth pipeline
JWKS reachable
License
Licensed

ASP.NET pack enabled

OTel Mesh — Traces

Fingerprint timeline

87fbf73b769b41959464ad55df07daeb 0 observations

Span + log activity for this fingerprint, ordered by timestamp.

No timeline observations

OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)

Operator actions

Operator actions

Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.

Signature: 83l1OfV82Bx1bsr1_DW2Dw | Processing: 13ms | Country: GB | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0 | First seen: 2026-07-25 03:50:24 UTC