You: Bot 100.0% Low
← Dashboard / Signature Detail
US

Unknown

Bot
Unknown
Policy: Silent Throttle
Probability
94 %
Confidence
91 %
Risk Profile
VeryHigh
Threat
None
Hit Count
7
Last Seen
48s ago

Analysis

Unknown on / - caught by Request patterns appear normal, IP appears normal: 144.172.98.xxx, Headers appear normal

Detection Signals

  • Heuristic model (late): 86 % bot likelihood (287 features) 1.78
  • Heuristic model (early): 59 % bot likelihood (18 features) 0.35
  • IP appears normal: 144.172.98.xxx 0.15
  • Headers appear normal 0.15
  • Request patterns appear normal 0.15
  • No bot marker in User-Agent (weak human lean; UA is easily spoofed) 0.05
Network Locale Headers Tool Transport Session Quality
Drifted
Generic Adblocker uBlock Origin
Drift vs
56.6%

Fingerprint Profile

TLS Version
Unavailable
HTTP Protocol
HTTP/1.1
Protocol Client
Unavailable
TCP OS Hint
Unavailable
Fingerprint Integrity
Consistent
UA Consistency
Consistent
Headless Indicator
Low
Datacenter IP
Clean

Browser modes same browser, different modes. One row per persisted mode

Mode Observations Maturity Shift from baseline Last seen
websocket-upgrade 9 9 0.43 (x requested with, header order hash, header case pattern) 19:04:21
bot-raw 8319 8319 0.03 (ua family, header case pattern, referer host family) 19:04:21
signalr-negotiate 127 127 0.40 (ua family, header order hash, referer host family) 19:01:55
sub-resource 492 492 0.41 (ua family, header case pattern, referer host family) 19:01:47
navigation 14 14 0.46 (custom header signature, upgrade insecure requests, header order hash) 12:11:32
5 modes across 8961 observations. See composite browser-mode fingerprints.
Endpoints Visited (2) Click to expand · stats unavailable
# Path
1 /
2 /api/v1/licensing/about
Raw Requests (7) Click to expand
Time Method Path Status Prob Conf Risk Profile Action Time
12:14:31 GET / 502 84 % 68 % High Silent Throttle 12.0ms
12:14:27 GET / 502 84 % 68 % High Silent Throttle 11.9ms
12:14:25 HEAD / 502 90 % 68 % VeryHigh Silent Throttle 11.3ms
12:14:25 GET / 502 90 % 88 % VeryHigh Silent Throttle 15.7ms
12:14:21 HEAD / 502 85 % 68 % High Silent Throttle 16.2ms
12:14:20 GET /api/v1/licensing/about 502 79 % 68 % High Silent Throttle 13.6ms
12:14:19 GET /api/v1/licensing/about 502 61 % 84 % Medium Allow 16.1ms

Bot Probability & Confidence History

StyloBot Detection Overhead (ms)

User Agent

SmarterMail-Scanner/1.0 (authorized-research)

Detector Contributions (18 detectors)

Detector Confidence Delta Timing (ms)
HeuristicLate
Heuristic model (late): 86 % bot likelihood (287 features)
+0.712 0.3
Heuristic
Heuristic model (early): 59 % bot likelihood (18 features)
+0.177 0.0
Ip
IP appears normal: 144.172.98.xxx
-0.150 0.0
Header
Headers appear normal
-0.150 0.1
Behavioral
Request patterns appear normal
-0.150 0.1
UserAgent
No bot marker in User-Agent (weak human lean; UA is easily spoofed)
-0.050 0.5
Http2Fingerprint
Using HTTP/1.1 instead of HTTP/2 (HTTP/2 rate: 0 % over 8 samples)
+0.050 0.0
TlsFingerprint
Using HTTP instead of HTTPS (uncommon for modern browsers)
+0.050 0.0
AI
AI analysis: borderline case, monitoring
+0.000 10.7
AiScraper
No AI scraper signals detected
+0.000 0.0
VerifiedBot
No known bot UA pattern
+0.000 0.0
SecurityTool
No security tools detected in User-Agent
+0.000 0.1
RequestHydrator
Request signals hydrated to sink
+0.000 0.0
Http3Fingerprint
Connection uses HTTP/1.1 (not HTTP/3)
+0.000 0.0
TcpIpFingerprint
Network fingerprint analysis complete (no anomalies detected)
+0.000 0.0
HeaderCorrelation
Single signature per header profile
+0.000 0.0
TransportProtocol
Transport protocol analysis complete
+0.000 0.0
FastPathReputation
No known patterns in reputation cache
+0.000 0.0

Signal Intelligence

request

protocol HTTP/1.1
accept_encoding gzip, deflate, zstd

risk

justification Classified Unknown (probability 0.84, confidence 0.68)
friendly_pin_trace not-applicable:botType=Unknown,yamlType=null,botName=null

Policy applied

Hit history

No sessions recorded yet.

Sessions are created when a visitor's activity gap exceeds 30 minutes.

Effective policy
Loading effective policy…
ASP.NET Pack — Auth health
JWKS health
OK

reachable

Auth pipeline
JWKS reachable
License
Licensed

ASP.NET pack enabled

OTel Mesh — Traces

Fingerprint timeline

32bb80482ffb48089559f74451ecff49 0 observations

Span + log activity for this fingerprint, ordered by timestamp.

No timeline observations

OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)

Operator actions

Operator actions

Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.

Signature: DQ_Od6lG8grx-8fhVSf2Qw | Processing: 12ms | Country: US | UA: SmarterMail-Scanner/1.0 (authorized-research) | First seen: 2026-07-25 12:14:19 UTC