Harvester exfil pattern: fingerprint probe followed by unauthenticated artifact
Detects a suspicious sequence of events where a host performs multiple reconnaissance-style probes (health checks, documentation, or OpenAPI definitions) followed within 10 minutes by access to sensitive artifact-related URLs on the same remote host. This pattern is indicative of an attacker profiling a target server for metadata and then proceeding to exfiltrate files or sensitive artifacts.
CQL

