Definition
Canonical reference for fwprobe behavior.
Display name
Firewall probing
How to read this signal
This annotator represents a behavioral pattern, not a claim of identity.
It’s designed to help you understand why certain traffic looks suspicious, automated,
probing, or exploit-oriented — and to support consistent reporting across the Syndu system.
Explanation
Flags patterns consistent with probing or mapping your firewall/policy surface: repeated hits on restricted endpoints, testing for differences in responses (403 vs 404 vs redirects), and attempts to infer what is blocked or protected. This annotator is about interaction with defense boundaries rather than payload injection specifically. Interpret alongside Never-200-like patterns, scan velocity, and your allow/deny decisions.