RedAmon
A security recon framework applies bounded Jev decisions to page classification and scan planning.
A security recon framework applies bounded Jev decisions to page classification and scan planning.
For each unresolved probed page, the planner sends a bounded page state and asks five Noul questions, one for each label: login_only, parked, default, placeholder, and error. The highest label at or above the 0.70 threshold is written as page_class with confidence and source metadata; if none reaches threshold, the result is app. Deterministic prefilter labels remain available when Jev is unavailable.
Is the page only a login or single-sign-on wall, with no application content reachable without credentials?
One probed URL's page state: URL, host, status code, content length, word and line counts, response time, CDN flag, title, server, CNAME, bounded headers, and body excerpt. Each page is asked separately.
Is this a domain-parking or domain-for-sale page?
One probed URL's page state: URL, host, status code, content length, word and line counts, response time, CDN flag, title, server, CNAME, bounded headers, and body excerpt. Each page is asked separately.
Is this a web server or vendor default landing page left in place?
One probed URL's page state: URL, host, status code, content length, word and line counts, response time, CDN flag, title, server, CNAME, bounded headers, and body excerpt. Each page is asked separately.
Is this a placeholder or empty holding page with no application behind it?
One probed URL's page state: URL, host, status code, content length, word and line counts, response time, CDN flag, title, server, CNAME, bounded headers, and body excerpt. Each page is asked separately.
Is this an error page rather than real content, such as a soft 404 or access-denied wall?
One probed URL's page state: URL, host, status code, content length, word and line counts, response time, CDN flag, title, server, CNAME, bounded headers, and body excerpt. Each page is asked separately.
A deterministic prefilter labels obvious default, parked, placeholder, login-only, and error pages; unresolved and already labeled pages can enter the Jev pass.
The planner deduplicates equivalent page states and asks Jev five Noul questions per page, within scan page and time budgets.
The winning class above threshold is stored on the URL entry and graph Endpoint. If no class reaches threshold, the label is app; unavailable or unanswered pages keep applicable prefilter behavior.
This applies typed decisions to reduce wasted security-recon effort on parked, default, placeholder, error, or login-only pages while making uncertainty fall toward continued application scanning. The source also bounds page count, request input, and total pass time.