You: Bot 100.0% Low
← Dashboard / Signature Detail
US

Headless Chrome

· HeadlessChrome / Linux Bot
Scraper
Policy: Silent Throttle
Probability
100 %
Confidence
93 %
Risk Profile
VeryHigh
Threat
None
Hit Count
11
Last Seen
36s ago

Analysis

Headless Chrome on /_content/Mostlyl... - caught by Known bot pattern: Headless Chrome, Same-origin browser fetch - Sec-Fetch-Site attestation pr..., Request timing shows natural human variation

Detection Signals

  • Heuristic model (early): 87 % human likelihood (19 features) 1.47
  • Known bot pattern: Headless Chrome 1.35
  • Heuristic model (late): 67 % bot likelihood (323 features) 0.84
  • Same-origin browser fetch - Sec-Fetch-Site attestation present 0.40
  • Request timing shows natural human variation 0.20
  • IP appears normal: 2604:a880:... 0.15
Network Locale Headers Tool Transport Session Quality
Drift vs
28.3%

Fingerprint Profile

TLS Version
TLSv1.3
HTTP Protocol
HTTP/2
Protocol Client
TLS_AES_256_GCM_SHA384
TCP OS Hint
Unavailable
Fingerprint Integrity
Suspect
UA Consistency
Flagged
Headless Indicator
Low
Datacenter IP
Clean

Browser modes same browser, different modes. One row per persisted mode

Mode Observations Maturity Shift from baseline Last seen
bot-raw 5008 5008 0.01 (ua family, priority, sec fetch pattern) 19:59:55
signalr-negotiate 20 20 0.53 (ua family, priority, sec ch ua brands ordered) 17:21:20
sub-resource 38 38 0.50 (priority, ua family, ip subnet) 14:26:09
navigation 27 27 0.62 (ua family, upgrade insecure requests, custom header signature) 11:36:09
websocket-upgrade 3 3 0.48 (ua family, cache control pragma, header order hash) 20:27:40
5 modes across 5096 observations. See composite browser-mode fingerprints.
Endpoints Visited (6) Click to expand · stats unavailable
# Path
1 /_content/Mostlylucid.BotDetection.UI/css/sb-components.css
2 /_content/Mostlylucid.BotDetection.UI/bot-detection-details.css
3 /_content/Mostlylucid.BotDetection.UI/vendor/css/boxicons.min.css
4 /dist/assets/index.css
5 /
6 /_content/Mostlylucid.BotDetection.UI/img/stylowall.svg
Raw Requests (11) Click to expand
Time Method Path Status Prob Conf Risk Profile Action Time
16:43:16 GET /_content/Mostlylucid.BotDetection.UI/css/sb-components.css 304 100 % 50 % VeryHigh Silent Throttle 12.5ms
16:43:15 GET /_content/Mostlylucid.BotDetection.UI/bot-detection-details.css 304 100 % 50 % VeryHigh Silent Throttle 12.7ms
16:43:15 GET /_content/Mostlylucid.BotDetection.UI/vendor/css/boxicons.min.css 304 100 % 50 % VeryHigh Silent Throttle 12.9ms
16:43:14 GET /dist/assets/index.css 304 100 % 50 % VeryHigh Silent Throttle 12.1ms
16:43:11 GET / 200 100 % 50 % VeryHigh Silent Throttle 13.8ms
16:42:44 GET /_content/Mostlylucid.BotDetection.UI/css/sb-components.css 200 100 % 50 % VeryHigh Silent Throttle 12.6ms
16:42:44 GET /_content/Mostlylucid.BotDetection.UI/vendor/css/boxicons.min.css 200 100 % 50 % VeryHigh Silent Throttle 13.0ms
16:42:43 GET /dist/assets/index.css 200 100 % 50 % VeryHigh Silent Throttle 12.3ms
16:42:43 GET /_content/Mostlylucid.BotDetection.UI/bot-detection-details.css 200 100 % 50 % VeryHigh Silent Throttle 13.2ms
16:42:42 GET /_content/Mostlylucid.BotDetection.UI/img/stylowall.svg 200 100 % 50 % VeryHigh Silent Throttle 13.6ms
16:42:39 GET / 200 100 % 50 % VeryHigh Silent Throttle 14.1ms

Bot Probability & Confidence History

StyloBot Detection Overhead (ms)

User Agent

Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/[phone] Safari/537.36

Detector Contributions (37 detectors)

Detector Confidence Delta Timing (ms)
Heuristic
Heuristic model (early): 87 % human likelihood (19 features)
-0.733 0.1
UserAgent
Known bot pattern: Headless Chrome
+0.900 0.5
HeuristicLate
Heuristic model (late): 67 % bot likelihood (323 features)
+0.337 0.3
Header
Same-origin browser fetch - Sec-Fetch-Site attestation present
-0.400 0.0
BehavioralWaveform
Request timing shows natural human variation
-0.150 0.3
Ip
IP appears normal: 2604:a880:...
-0.150 0.0
Behavioral
Request patterns appear normal
-0.150 0.1
CacheBehavior
Normal cache behavior detected
-0.150 0.1
Inconsistency
No header/UA inconsistencies detected
-0.150 0.0
TlsFingerprint
TLS connection appears normal
-0.150 0.0
VersionAge
Browser/OS versions appear current
-0.050 0.0
AI
AI analysis: borderline case, monitoring
+0.000 9.6
Llm
LLM detection disabled or unavailable
+0.000 0.0
Intent
Session intent: browsing (threat=0.05, band=None)
+0.000 0.5
AiScraper
No AI scraper signals detected
+0.000 0.0
Similarity
No prior visitor signatures to compare against yet
+0.000 0.0
StreamAbuse
Stream abuse check - non-streaming request
+0.000 0.0
VerifiedBot
No known bot UA pattern
+0.000 0.0
SecurityTool
No security tools detected in User-Agent
+0.000 0.1
SessionVector
Session tracking active (4 requests, 0 prior sessions)
+0.000 0.2
CookieBehavior
No Set-Cookie headers observed
+0.000 0.0
PiiQueryString
Query string contains PII parameters: token
+0.000 0.0
ReputationBias
No learned reputation patterns matched
+0.000 0.0
ClaimedIdentity
UA already identified as known bot
+0.000 0.0
ContentSequence
Sequence on track at position 3
+0.000 0.1
ProjectHoneypot
Skipped: ProjectHoneypot is disabled in configuration
+0.000 0.0
ReactivePattern
No prior error events to analyze
+0.000 0.0
RequestHydrator
Request signals hydrated to sink
+0.000 0.0
Http2Fingerprint
HTTP/2 analysis complete (no anomalies detected)
+0.000 0.0
Http3Fingerprint
Connection uses HTTP/2 (not HTTP/3)
+0.000 0.0
ResponseBehavior
Response coordinator not configured
+0.000 0.0
TcpIpFingerprint
Network fingerprint analysis complete (no anomalies detected)
+0.000 0.0
HeaderCorrelation
Single signature per header profile
+0.000 0.0
ResourceWaterfall
Insufficient document requests for analysis
+0.000 0.1
TransportProtocol
Transport protocol analysis complete
+0.000 0.0
FastPathReputation
No known patterns in reputation cache
+0.000 0.0
MultiLayerCorrelation
Cross-signal consistency check complete (not enough data to compare)
+0.000 0.1

Signal Intelligence

h2

protocol h2

referrer

domain stylobot.net

request

protocol HTTP/2
accept_encoding gzip, br

risk

justification Classified Scraper (probability 1.00, confidence 0.50)
friendly_pin_trace not-applicable:botType=Scraper,yamlType=Scraper,botName=Headless Chrome

tls

cipher TLS_AES_256_GCM_SHA384
Version TLSv1.3
version TLSv1.3

Policy applied

Hit history

No sessions recorded yet.

Sessions are created when a visitor's activity gap exceeds 30 minutes.

Effective policy
Loading effective policy…
ASP.NET Pack — Auth health
JWKS health
OK

reachable

Auth pipeline
JWKS reachable
License
Licensed

ASP.NET pack enabled

OTel Mesh — Traces

Fingerprint timeline

5a36b9e9b2994562b9871ac69b1d975f 0 observations

Span + log activity for this fingerprint, ordered by timestamp.

No timeline observations

OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)

Operator actions

Operator actions

Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.

Signature: HZvGGNC-JVST4BadV6ZRXg | Processing: 12ms | Country: US | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/[phone] Safari/537.36 | First seen: 2026-07-19 16:42:39 UTC