basquetWi + New ticket

New ticket

Sub-ticket of PLUTO-447 Investigate not-found capture-leg bypassing the scanner down-tier: at 06-28 01:28 paths that DO match SCANNER_PROBE_RE (/wp-content, /cgi-bin, /.well-known, /admin/controller/extension, /zup.php73, /randkeyword.PhP7) logged at warn/navigation, while IDENTICAL paths logged info/malicious at 01:40 + in the 08:46 sweep (same deploy, ~12 min apart). tierForNotFound down-tiers these path-only/any-referer BEFORE reason logic, so a warn outcome means those rows did NOT pass the SCANNER_PROBE_RE branch — consistent with a different persist leg (PLUTO-182 not-found capture-on-redirect emitting phantom rows that bypass the classifier). Coder read: does the capture leg run not-found-classify's down-tier, or persist warn directly? Benign-impact (rows retained) but a sliver of scanner hits intermittently page at warn. Relates to the routeResolves discriminator (pluto-notfound-capture-redirect-overfire). Low-pri. · pluto