Definition
Canonical reference for sfp behavior.
Display name
Sensitive file probing
How to read this signal
This annotator represents a behavioral pattern, not a claim of identity.
It’s designed to help you understand why certain traffic looks suspicious, automated,
probing, or exploit-oriented — and to support consistent reporting across the Syndu system.
Explanation
Flags attempts to access files and paths that are commonly sensitive or frequently exposed by mistake (configuration files, environment files, backups, admin panels, hidden resources). This annotator is especially useful for explaining opportunistic scanning behavior. In reports, show targeted resources grouped by category and the observed outcomes (404/403/200) without implying compromise.