FLUX FLEET — INTEL BRIEFING №20
Period: 2026-09-13 07:33 – 2026-09-14 07:33 UTC (24h digest window, day 19 of operations) Sources: 7 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East), ru-edge-1 (Russia), netcup-ts + sponge-01-ts + frantech-ts (deception-only, no canaries) Confidence: High (direct observation; 19-day baseline, every result-tag spike attributed by spot query)
The digest window runs 07:33 UTC 09-13 to 07:33 UTC 09-14. The prior briefing №19 closed at 07:36 UTC 09-13, so this window holds only a 3-minute overlap segment (10
/-onlytarpit rows on farm — recounted as new here). All times below are raw log timestamps (UTC; the-04-suffixed flux rows are local wall clock, 4 h behind). The +4 h ingest cast widens SQL windows by 4 hours.
BLUF
The credential funnel moved again: 18 credentials minted by one ai-devbox-1 burst at 17:34:09–21 UTC 09-13 all reached AWS within 6 minutes — 52 of 71 use events from 45.67.211.147 (G-Core Labs) under aws-sdk-go-v2 and one scan burst from 103.26.8.88 (GoMami SG), all denied except sts:GetCallerIdentity. This is the second mint-to-use conversion in fleet history. It is the first with a visible mint collector IP and the largest single-batch use (18 credentials vs №19's 3). A new empty-IP .env census wave hit both EU nodes with a 511-path wordlist (510 shared) and minted once. Two smaller census passes ran on control-1 and ru-edge-1 with wordlists that overlap the 112-path core. METADATA-HUNT's empty-IP variant ran its second day (control 06:19, aidev 17:34–18:55, farm 18:58, netcup 21:47, sponge 11:07), and one new Google-hosted runner worked with its source IP intact — 136.117.52.210, 385 events in 14 seconds, 26 mints, the largest single-IP haul since the fleet began. LIBREDTAIL-KIT ran its sixth window with zero captured POST bodies for the second consecutive cycle.
Key Judgements
- The 17:34 aidev burst is the fleet's first fully-traced mint→use chain: mint IP visible, use IPs recorded, latency under 6 minutes. Flux logs carry no
clientIpon the 17:34 burst rows (the 17:34:09–18issuedrows are all empty-IP), but Tracebit credential labels pin the batch to 18 distinct mints in 12 seconds. The first AWS call landed at 17:39:50 UTC from 45.67.211.147. A second IP, 103.26.8.88, ran 7 operations at 17:40:18–47. (High confidence on the trace — Tracebit labels and flux rows agree to the second. Moderate on operator identity: two use IPs and an unattributed mint leave resale possible, and 45.67.211.147 appears nowhere in flux logs.) - A new 511-path
.envcensus campaign ran twice on the EU nodes; the wordlist is a 510-of-511 match across both runs and a 510-of-513 overlap with the standing Chrome/126 census family. farm ran it at 02:45 underChrome/126.0.0.0and aidev at 06:20–06:42 under the same UA, 514 events each. The empty-IP variant minted 1 on aidev (/.env) and failed 1 on farm. (High confidence on the linkage — identical wordlists and UA. The operator is unknown; every prior Chrome/126 census run traced to standing actors 194.180.49.37 and 91.245.74.31, which did not return.) - 136.117.52.210 is the first named METADATA-HUNT-class runner since №14 to mint 26 credentials in one burst and hold them. The IP (Google LLC) ran 385 events, 262 paths, 33 rotating AI-crawler forgeries, 26 mints plus 5
vite-fs-issuedrows, 7 upstream 400s, in one 14-second pass on canary-farm-1 (00:41:14–28). Its wordlist carries the@fstraversal,ssrf-relay-*,__aws_leak_probe-class markers,/mcptooling probes, and graphql introspection. (High confidence on the facts. No AWS use from any of its 26 credentials had fired by window close — the hoard is hostile-held inventory.) - CURL-SWEEP missed its third consecutive window. Only scattered
curl/7.74.0singles ran this cycle (7-event bursts on aidev 21:36, control 23:36, ru-edge 06:15, farm 05:03 — 1 mint-free/.envwave each) with none of the 07:59–08:55 UTC fleet-wave shape of №18–№19. The daily-schedule read now fails; the template looks retired or dormant. (Moderate confidence — absence across one window after two on-schedule runs; a fourth miss closes the question.)
Active Campaigns (day 19 status)
Recurring campaigns carry ⟳ and their registry names. First-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity.
⟳ METADATA-HUNT (GCP crawler census, empty-IP escalation) — hostile, fleet-wide
- Actors: The empty-IP variant ran 5 bursts this window: control-1 06:19–06:26 09-13 (114 events / 112 paths,
Chrome/45.0.2454.101, 2 mints — one at 06:19:34, one at 08:50 under anOPR/45forgery), aidev 17:04–18:55 (748 + 688 events, 5 mints + 27×400), farm 18:58:50–57 (113not-handled, 19ssrf-relay-*, 0 mints, 13×400), netcup 21:47–21:48 (618 events in 21 s, 0 mints), sponge 07:07 09-13 (40 marker rows, 0 mints). Named runner with source IP: 136.117.52.210 (Google LLC), farm, 00:41:14–28 09-14, 385 events / 262 paths in 14 s, 26 mints. - TTPs: Unchanged GCP/AI-config template:
/.envvariants,/@fs/proc/self/environ,/@fs/root/.env,/.mcp.json,__aws_leak_probemarkers,ssrf-relay-aws-index/ssrf-relay-aws-role-list. UA rotation persists: 465+ forged crawler strings per burst, per-request rotation. The 136.117.52.210 run adds graphql introspection (/graphql,/api/graphql,/v1/graphql, 3 POSTs, 86-byte bodies not captured) and an MCP tools-call POST to/mcp(168 bytes, body not captured), the first named-IP MCP probe of this campaign. - Assessment: The campaign now runs two shapes: the empty-IP fleet-wide wave (sourceless, low mint yield) and the named single-runner burst (high mint yield). 136.117.52.210's 26 mints make it the largest single-collector haul since the /46 block's 25-mint batches. The mint failures (upstream 400s) continue to track burst speed, not capability.
⚠ ENV-CENSUS-3 (511-path .env wordlist, empty-IP, Chrome/126 UA) — hostile, new name
- Actors: Unattributed. farm 02:45:18–49 09-14 (514 events / 511 paths, 0 mints, 1×400) and aidev 06:20–06:42 (514 events / 511 paths, 1 mint at
/.env, 0×400). Wordlist overlap between the two runs: 510 of 511 paths. Overlap with the standing Chrome/126 census family (09-04/05/06/08, 743 distinct paths): 510 of 513 — the same wordlist, pruned and re-run. - TTPs: The
.env-variant directory fanout with webshell-sweep (/index1.php,/test_phpinfo5.php), yii2 debug, sftp-config, andwp-config-backup.phpfamilies. Single UA, single pass per node, 31 s on farm, 22 s spread on aidev. - Assessment: Third generation of the CREDSWEEP-lineage wordlist. Prior runs attributed to 194.180.49.37 (09-04) and 91.245.74.31 (09-05, 09-06), both of which broke their streaks this window; the operator either retired the named IPs or the template now runs unattributed like OMEGA-SWEEP did after №15. Promotion from ENV-CENSUS-2 lineage is warranted because the empty-IP propagation and the 511-path list are new.
⟳ OMEGA-SWEEP (107-family config census, forged Googlebot/2.1) — hostile, contracted to a single-node return
- Actors: Unattributed. canary-farm-1 21:18:04–18 09-13: 1,500 events / 1,342 paths / 14 s, 0 mints, 7×400. Stray single events under the same forged UA on sponge (16:22), control (07:14 09-14), and farm (7 rows inside the 136.117.52.210 window).
- TTPs: The census ran a 1,342-path list — 80% larger than the aidev core of №14 (743 paths) and larger than №19's control run (1,033). Forged
Googlebot/2.1on every row. Result mix holds the 107-family shape:wp-config-error27,app-config-python-error25,app-config-php-error22,fake-git-error22,webshell-sweep-observed14,phpmyadmin-login11. - Assessment: Fourth window of expansion, then contraction to one node. The /46 block (94.154.46.x) minted nothing this window — first absence since №16. The 1,342-path list growth says the operator still develops the census even while hiding its source.
⟳ REGISTRY-HUNT (LeakIX weblogic/confluence/docker-registry walk) — borderline scanner, six-IP wave
- Actors: 6 runners this window, same count as №19: 4 named DigitalOcean runners (209.38.248.17 aidev, 167.71.175.236 aidev, 157.230.19.140 farm, 159.89.12.166 farm) plus 2 empty-IP runners, 39 events per named IP at 20:40–20:43 UTC, 78 events per empty-IP runner. Two UA variants persist (
l9scan/2.0.632323…aidev,l9scan/2.0.234313…farm), 156 events per variant. - TTPs: Unchanged 12-step walk: tarpit → WebLogic console → server-status → Confluence → WHM/cPanel subdomains → docker-registry
/v2/internal/.... Zero mints this window — first time the wave has minted nothing since №16. - Assessment: LeakIX stays borderline per registry. The named-runner set is stable across windows (the same 4 IPs recur since 08-29), which reads as a scheduled scanner with a fixed runner pool rather than rotation.
⚠ CREDENTIAL-DRAIN (17:34 mint burst + AWS consumption) — hostile, new
- Actors: Mint side unattributed (empty-IP rows on aidev 17:34:09–22, forged AI-crawler UAs: Slackbot-LinkExpanding, GPTBot/1.4, OAI-SearchBot/1.4, ChatGPT-User/1.0, Claude-User/1.0). Use side: 45.67.211.147 (G-Core Labs S.A., US) — 70 events,
aws-sdk-go-v2/1.46.0; 103.26.8.88 (GoMami Networks, SG) — 7 operations at 17:40:18–47. - TTPs: 18 credentials minted at
/.env,/app/.env,/config.js,/@fs/root/.aws/credentials,/proc/self/environ, and siblings, then used within 6 minutes. Operation set:sts:GetCallerIdentity42 (success),DescribeInstances23,ListBuckets2,GetAccountSummary2,ListTopics1,ListFunctions201503311 (all denied,Client.UnauthorizedOperation). The 45.67.211.147 stream ran in repeated Describe→GetCallerIdentity pairs every 10–60 minutes for 11 hours — a polling loop, not a burst. - Assessment: Two different egress IPs consuming one mint batch points at a credential loader, not a browser session. The 11-hour cadence says the consumer treats the keys as a renewable feed: mint → enumerate → re-check until the 12-hour TTL. This is the fastest and largest conversion the fleet has traced, and it validates the fleet's deny-first IAM posture as the load-bearing control.
⟳ LIBREDTAIL-KIT (phpunit RCE + dropper) — hostile, sixth window, bodies still missing
- Actors: Unattributed. 6 runs fleet-wide: aidev 51 events (10:01–02:09), farm 134, control 129, frantech 99, ru-edge 49 (one 1.6-second burst 13:48), sponge 98. 84 POSTs fleet-wide, zero captured
bodyPreview. - TTPs: Template unchanged:
phpunit-eval-stdinprobe across 20+eval-stdin.phppaths, thenPOST /index.phpandPOST /bin/sh. The digest attributes sponge'sphpunit-eval-stdin75-event spike (infx on a first-full-window baseline) to this kit's 74 events. - Assessment: Second consecutive window with no dropper payload captured. Either the condensed feed lost
bodyPreviewfor these rows in both cycles (unlikely — the wp-login bodies captured fine) or the template stopped sending the dropper this week. The staging host remains unmeasured.
⚠ MALWARE-DICT-2 (IoT dropper-URL dictionary replay, dual-node) — hostile, new name
- Actors: Unattributed. control-1 486 events / 174 paths and ru-edge-1 481 events / 174 paths, byte-identical timing on both nodes (first rows within 0.6 s of each other at 09:12:49 09-13, matching hourly bursts through 06:43 09-14), empty UA on every row.
- TTPs: The
/bins/*and/hiddenbin/boatnet.*dropper families ran the same hourly pass on both fresh-IP nodes:/bins/x86.64,/bot.sh4,/z/mpsl,/0010101010100101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.{spc,arm6,arm7},/kitty.*,/lol.*,/i-5.8-6.Sakura,/HBTs/top1miku.m68k. - Assessment: This is the MALWARE-DICT loop shape (URLhaus-style dictionary replay) with two differences that justify a separate name: it runs synchronized on two nodes, and it runs empty-UA with no
/etc-style companion probes. Synchronized timing is stronger evidence of one operator than the №13–№14 Pfcloud loop, which ran on a single node. The wordlist overlap check (174/174 shared paths) pins the campaign identity.
Standing actors (persistence check)
- 136.117.52.210 (Google LLC) — first-ever appearance, 385 events, 26 mints. Watch: if it returns on any node, the 1:1 mint-to-event ratio pattern (like 40.87.20.23 in №19) makes it a collector signature, not a scanner.
- 40.87.20.23 (Azure) — returned on schedule at the window edge: farm
/.envmint at 07:10:41 09-13, its 2nd all-time event, 2nd mint. The 1:1 events-to-mints ratio across two nodes now holds for both its appearances. - Absent: 176.65.148.71 (broke a 6-visit streak), 194.180.49.37 and 91.245.74.31 (the Chrome/126 census pair — the census template ran unattributed instead), 80.94.95.211 (2nd absent window), 45.148.10.238, 91.245.74.31, 213.209.159.x, 204.76.203.x (MALWARE-DICT original loop silent), 43.228.157.68, 193.24.123.123, 35.245.185.138 (the №19 use IP), 136.70.175.146 (the №18 named runner, 3rd idle), the 94.154.46.x block entirely, and 159.26.110.179 (the №14 GetCallerIdentity actor).
- NIGHTAGENT — third consecutive idle window. Zero
NightAgentmarkers, zero GitHub dropper fetches. - XMLRPC-BRUTE — third consecutive silent window (3 stray
/xmlrpc.phpGETs on aidev, no POSTs). - frantech Chrome/114 crawler — 469 events / 469 paths across the window (03:50–04:44), a standing single-node census that №19 sized at 349 paths. Slow growth, same shape.
Canary credentials
Summary
53 Tracebit alert(s) fired in the window (71 use events across 18 credentials). Fleet sensors minted 37 credentials to 1 collector IPs; 18 credential(s) reached AWS.
Use outcomes: 42 success, 29 failure.
Denied operations: DescribeInstances×23, ListBuckets×2, GetAccountSummary×2, ListTopics×1, ListFunctions20150331×1.
42 call(s) succeeded: GetCallerIdentity. Successes leak identity at most; treat any success beyond sts:GetCallerIdentity as a finding.
Mint → use funnel
| Metric | Count |
|---|---|
| Credentials minted (fleet, window) | 37 |
| Distinct collector IPs | 1 |
| Credentials used in AWS (alerts) | 18 |
| Credentials stolen, no observed AWS use in window | 19 |
Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):
| Theft IP | Sensor | Mints (window) | Creds used in AWS | Use IPs | Operations | Mint history (6d) |
|---|---|---|---|---|---|---|
136.117.52.210 |
canary-farm-1 | 26 | 0 | 0 | — | 26 mints since 2026-09-14 00:41 |
unknown |
(outside flux window) | 0 | 18 | 2 | DescribeInstances, GetAccountSummary, GetCallerIdentity, ListBuckets, ListFunctions20150331, ListTopics | no flux mints in history window |
Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):
None: 32 mints, 2026-09-12 08:14 → 2026-09-14 06:30136.117.52.210: 26 mints, 2026-09-14 00:41 → 2026-09-14 00:41136.67.37.69: 25 mints, 2026-09-08 19:55 → 2026-09-08 19:5534.22.137.199: 25 mints, 2026-09-07 17:26 → 2026-09-07 17:2634.32.131.244: 25 mints, 2026-09-11 21:44 → 2026-09-11 21:4434.6.12.67: 25 mints, 2026-09-09 09:09 → 2026-09-09 09:0934.83.24.21: 25 mints, 2026-09-07 05:10 → 2026-09-07 05:1035.252.125.133: 25 mints, 2026-09-08 18:51 → 2026-09-08 18:52167.99.79.44: 12 mints, 2026-09-08 19:11 → 2026-09-11 18:1994.154.46.249: 12 mints, 2026-09-11 13:47 → 2026-09-11 13:4894.154.46.245: 10 mints, 2026-09-10 16:25 → 2026-09-10 16:2594.154.46.246: 10 mints, 2026-09-12 04:12 → 2026-09-12 04:1394.154.46.248: 10 mints, 2026-09-08 07:51 → 2026-09-08 07:5180.94.95.211: 6 mints, 2026-09-07 21:08 → 2026-09-12 02:32102.220.161.87: 4 mints, 2026-09-07 23:07 → 2026-09-09 13:44136.70.175.146: 4 mints, 2026-09-12 06:33 → 2026-09-12 06:33142.93.129.190: 4 mints, 2026-09-07 20:16 → 2026-09-10 20:23160.177.217.115: 4 mints, 2026-09-11 21:02 → 2026-09-11 21:43176.65.144.71: 4 mints, 2026-09-09 21:56 → 2026-09-09 21:5641.140.11.235: 3 mints, 2026-09-08 06:34 → 2026-09-08 06:45
Canary-use attribution (briefing prose)
All 18 used credentials came from one 12-second mint burst on ai-devbox-1 at 17:34:09–21 UTC 09-13. The flux-side rows for that burst are empty-IP (5 issued rows visible, 27 upstream 400s); Tracebit's credential labels pin all 18 mints to that burst regardless of what the flux feed logged. The consumer opened with DescribeInstances at 17:39:50 — 5 minutes 41 seconds after the first mint. One credential then ran a second scan from 103.26.8.88 at 17:40:18: GetCallerIdentity success followed by GetAccountSummary×2, DescribeInstances, ListBuckets×2, ListFunctions20150331, ListTopics, all denied. The rest of the batch stayed on 45.67.211.147 in a Describe→GetCallerIdentity polling loop that ran to 04:47 UTC 09-14, inside every credential's 12-hour TTL.
The use IP 45.67.211.147 (G-Core Labs, an-announced-us Manassas block) appears nowhere in flux logs, all-time or window — same pattern as №19's 35.245.185.138. G-Core is a CDN/anycast provider, so the IP may be a rotating egress, not a fixed host. The two-IP split (one steady consumer, one burst enumerator) matches an automated credential-vetting tool rather than a human session: load the key, run GetCallerIdentity, attempt the inventory calls the deny policy blocks, record, move to the next key. What remains unproven: whether 45.67.211.147 is the same party that scraped the trap, or a downstream consumer of a resale chain. The 5-minute latency makes resale unlikely but does not exclude an automated handoff.
The None collector row (32 mints, 09-12 08:14 → 09-14 06:30) carries the empty-IP batches: the METADATA-HUNT waves, the Chrome/126 census mint, and the control-1 and ru-edge singles. 136.117.52.210's 26 mints show as unused in this window's Tracebit pull — the mint→use check for its TTL window (expires by 12:41 UTC 09-14) is the first item for the next cycle.
Fleet Observations
- Canary economics: 39 mint rows to 5 named/collectable IPs (digest: aidev 6, farm 30, control 2, ru-edge 1); 75 upstream 400 failures (aidev 27, farm 33, control 14, ru-edge 1). Failure ratio 1.9:1, down from №19's 3.6:1. All mints
aws-type. The digest's 39 counts rawissuedrows; the Tracebit section's 37 counts distinct credentials — the difference is mint rows the flux feed logged with non-issuedresults (the 17:34 burst logged/config.jsaswebapp-config-bundle-jswhile Tracebit minted it). - XFF forgery: 646 requests carried an
X-Forwarded-Forheader; 0 multi-entry chains, 0 all-internal127.0.0.1rows — the fleet-side fix held for a tenth window. - Attribution gap widened: 13,933 of 15,047 window rows (92.6%) carry an empty
clientIp— 100% on all five no-canary/certless nodes, 95.0% on aidev, 88.2% on farm. Every campaign in this briefing except REGISTRY-HUNT's 4 named runners and the wp-login brute pool ran unattributed. The socket-peer fix (ops repo, carried since №17) remains the highest-value change available. - Control discovery velocity: day 19 cell: 3,152 events, 0 attributable IPs (digest shows 1 uniq = the NULL group). The node logged +3% events over baseline on an all-empty-IP feed. Ramp series for the record: 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108 → 120 → 110 → 78 → blind → blind → blind → 51 (4 h) → 52 → 0 real.
- TLS/attribution posture: farm 511 https events (598 Host-header hits on
sso.rightabouteverything.show), aidev 132 https oninference.fapthropic.com, the five certless nodes 0. Commodity IoT probes (/boaform, TP-Link diag) absent this window after their №19 first appearance. - Result-tag spikes: all attributed. farm's 33×
wp-config-errorand 30×app-config-php-errorare the OMEGA 21:18 census; the 5×env-production-error/app-config-*-errorclusters on farm are the METADATA-HUNT 18:58 burst and the Chrome/126 census; ru-edgenot-handled12.6× is the MALWARE-DICT-2 dictionary (611 distinct paths, most of them one-off dropper URLs); spongephpunit-eval-stdininfx is LIBREDTAIL's first sponge run; frantech/netcup/ru-edge infx ratios are first-full-window baselines for the new nodes. - Mint-label quirk (new): Tracebit mints can carry flux results other than
issuedwhen the trap's 200-family result classification wins. The 17:34/config.jsmint row loggedwebapp-config-bundle-js. Digest mint totals therefore undercount by however many mint rows fell into 200-family result labels; count credential batches from Tracebit labels, not flux results, when the two disagree.
SSH/telnet honeypot (frantech-ts — single sensor, not fleet-wide)
- New commands: zero. All 56 distinct commands this window were seen before. The 1,720-event
uname -s -v -n -r -mpair (2 IPs) and the 108-IPrm -rf .ssh+ authorized-keys inject remain the load-bearing recurring set. - Funnel: 334 sources sent credentials → 237 got a shell (71%) → 148 ran a command (62% of shell-getters, 44% of sources). Event level: 25,510 attempts → 14,660 accepted logins → 7,000 commands (48% of accepted logins run something). The per-login conversion held from №19.
- Credentials: 9,267 distinct pairs, 0 new. Concentration is the signal: the
345gs5662d34/3245gs5662d34family owns the top 5 rows (2,282 attempts across 4 usernames) — a single wordlist family, commodity noise.
Gaps / Next Collection
- 136.117.52.210's 26-credential TTL window. The batch minted 00:41 UTC 09-14; TTL expires by 12:41. Pull Tracebit alerts for 09-14 00:41–13:00 at the next cycle's start — any AWS call from that batch ties the named METADATA-HUNT runner to a consumer for the first time with the mint IP on record.
- 45.67.211.147 follow-through. The Describe→GetCallerIdentity loop ended 04:47 UTC. Pull the CloudTrail set for the 18 credentials' full TTLs — a second consumer IP or any post-TTL callback extends the chain. 103.26.8.88 (GoMami SG) ran 7 operations once; treat as a different stage of the same pipeline until it returns.
- LIBREDTAIL dropper capture, second pass. Two consecutive windows with zero POST bodies across 84 POSTs. Next cycle, check the raw node-side flux logs directly (before the condensed feed) for one run — if bodies exist there, the digest feed is the loss point; if not, the template dropped its payload stage.
- ENV-CENSUS-3 recurrence. The 511-path list ran twice in 4 hours. If a third run lands on control-1 or a no-canary node, the campaign is fleet-wide automation; watch for the named IPs (194.180.49.37, 91.245.74.31) to return and re-claim it.
- Socket-peer logging for headerless requests (carried from №17–№19). 92.6% of this window's rows are unattributed. Four campaigns (METADATA-HUNT empty-IP wave, ENV-CENSUS-3, CURL-SWEEP, MALWARE-DICT-2) attribute at once if it ships. No fleet-side action from this workflow.
- CURL-SWEEP retirement call. Third consecutive miss. One more silent window and the registry entry moves to standing-paused.
Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-14.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (136.117.52.210), plus 28 ad-hoc v_full queries (METADATA-HUNT marker distribution, Chrome/126 census linkage and wordlist-overlap matrix, OMEGA-SWEEP farm return, MALWARE-DICT-2 dual-node timing, REGISTRY-HUNT named-runner history, wp-login pair census, standing-actor persistence batch, empty-IP share per sensor, tracebit-http-error mint attribution, config.js mint-label quirk) and the Tracebit canary-section generator plus a per-alert tracebit-alerts logs pull (53 alerts, 71 use events).