Profil de menace
Activité suspecte — risque 44/100 (Moyen) — MITRE T1046 — confiance 100 % — via HTTP — multi-protocole (15 protocoles · 5 min)
Période analysée : 2026-07-07 → 2026-08-06
Activité suspecte — risque 44/100 (Moyen) — MITRE T1046 — confiance 100 % — via HTTP — multi-protocole (15 protocoles · 5 min)
Campagne multi-ports détectée sur une fenêtre courte
Activité suspecte — risque 44/100 (Moyen) — MITRE T1046 — confiance 100 % — via HTTP — multi-protocole (15 protocoles · 5 min)
Synthèse décisionnelle honeypot — seuil de listing maintenu à 1 événement qualifié.
Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance 100 % — Score WAF 48 · Bonus corrélation +18 · 2 tag(s) WAF
ASN 63737 · 103.190.80.0/23 · APNIC — 8 pair(s) ASN/FAI listé(s) — activité locale élevée vs pairs · 60 événements sur la période pour cette IP.
Même FAI VIETSERVER SERVICES TECHNOLOGY COMPANY LIMITED — corrélation indicative.
Cette IP touche plusieurs services simulés (pas seulement le web).
Origine réseau déclarée
Opérateur et dernière activité ban
Score capteur — surveiller, investiguer ou bloquer.
Les dates De/À priment sur la période. Affinez protocole, port, service et classification.
60 événements filtrés — activité quotidienne
Top ports ciblés sur les dernières 24 heures
SSH 22, RDP 3389, HTTP alternatifs…
Web, SSH, SAP, scans…
Intensité par jour et heure (UTC capteur)
60 événement(s) — page 1/2
| Horodatage | Proto | Port | Service | Classification | Sévérité | Risque | Actions |
|---|---|---|---|---|---|---|---|
| TCP | 8089 · SPLUNK | splunk | Scan de ports port scan syn · via SPLUNK:8089 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
SPLUNK
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
8089
Chemin / cible
—
Service
SPLUNK
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 8008 · HTTP | http | Scan de ports port scan syn · via HTTP:8008 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8008
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=JMNHspbPwZI7lAxNyD3bDLO9 HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=JMNHspbPwZI7lAxNyD3bDLO9 HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8088 · HTTP | http | Scan de ports port scan syn · via HTTP:8088 · (reconnaissance) | Élevée | Moyen · 44 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8088
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 44
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=yYKSMr2nD3cWlG0QCVZjQTrQ HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=yYKSMr2nD3cWlG0QCVZjQTrQ HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8084 · HTTP | http | Scan de ports port scan syn · via HTTP:8084 · (reconnaissance) | Élevée | Moyen · 44 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8084
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 44
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=Zl8q4TdziE-_v4ZPZYT-_8ew HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=Zl8q4TdziE-_v4ZPZYT-_8ew HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8082 · HTTP | http | Scan de ports port scan syn · via HTTP:8082 · (reconnaissance) | Élevée | Moyen · 43 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8082
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 43
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=A6RCb88RN5fFkcHkUrtGy0aS HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=A6RCb88RN5fFkcHkUrtGy0aS HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 7001 · HTTP | http | Scan de ports port scan syn · via HTTP:7001 · (reconnaissance) | Élevée | Moyen · 44 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
7001
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 44
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=FUVO9qGmA3oPBug3ovk-74bL HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=FUVO9qGmA3oPBug3ovk-74bL HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8089 · HTTP | http | Scan de ports port scan syn · via HTTP:8089 · (reconnaissance) | Élevée | Moyen · 44 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8089
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 44
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=SfYemu01yZjT_MnCAQdfNtVb HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=SfYemu01yZjT_MnCAQdfNtVb HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 7001 · HTTP | http | Scan de ports port scan syn · via HTTP:7001 · (reconnaissance) | Élevée | Moyen · 44 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
7001
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 44
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=vFyFuVP6F0iUQvc8MYtOfX-l HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=vFyFuVP6F0iUQvc8MYtOfX-l HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8089 · HTTP | http | Scan de ports port scan syn · via HTTP:8089 · (reconnaissance) | Élevée | Moyen · 44 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8089
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 44
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=dst_imvFZbf3BWTU5JWeBHYZ HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=dst_imvFZbf3BWTU5JWeBHYZ HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 9443 · HTTPS | https | Scan de ports port scan syn · via HTTPS:9443 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTPS
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
9443
Chemin / cible
—
Service
HTTPS
Payload
GET http://oracle.vanhoang.id.vn:18451/?nonce=-GfK_AjyKLnmPp3PGIIipg6C HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 3 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
HTTPS alt 9443 probe
User-Agent
—
Règles WAF
—
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=-GfK_AjyKLnmPp3PGIIipg6C HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=-GfK_AjyKLnmPp3PGIIipg6C HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8008 · HTTP ALT 8008 | http-alt-8008 | Scan de ports port scan syn · via HTTP ALT 8008:8008 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTP-ALT-8008
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
8008
Chemin / cible
—
Service
HTTP ALT 8008
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 8443 · HTTPS | https | Scan de ports port scan syn · via HTTPS:8443 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTPS
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
8443
Chemin / cible
—
Service
HTTPS
Payload
GET http://oracle.vanhoang.id.vn:18451/?nonce=loLxPuJjjrUGHuFeVSRAAYxj HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
User-Agent
—
Règles WAF
—
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=loLxPuJjjrUGHuFeVSRAAYxj HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=loLxPuJjjrUGHuFeVSRAAYxj HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 9002 · HTTP | http | Scan de ports port scan syn · via HTTP:9002 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
9002
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=R-2RmFXoBLViJ6yT-ZMofd2u HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=R-2RmFXoBLViJ6yT-ZMofd2u HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8889 · HTTP | http | Scan de ports port scan syn · via HTTP:8889 · (reconnaissance) | Élevée | Moyen · 43 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8889
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 43
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=8KRHc2YtYtwBC8yRr7hL3KM3 HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=8KRHc2YtYtwBC8yRr7hL3KM3 HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8088 · HTTP ALT 8088 | http-alt-8088 | Scan de ports port scan syn · via HTTP ALT 8088:8088 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTP-ALT-8088
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
8088
Chemin / cible
—
Service
HTTP ALT 8088
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 8084 · HTTP ALT 8084 | http-alt-8084 | Scan de ports port scan syn · via HTTP ALT 8084:8084 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTP-ALT-8084
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
8084
Chemin / cible
—
Service
HTTP ALT 8084
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 3128 · HTTP | http | Scan de ports port scan syn · via HTTP:3128 · (reconnaissance) | Élevée | Moyen · 44 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
3128
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 44
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=NN3zvEsI1XiUBiq_gRp1RBSf HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=NN3zvEsI1XiUBiq_gRp1RBSf HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8082 · HTTP ALT 8082 | http-alt-8082 | Scan de ports port scan syn · via HTTP ALT 8082:8082 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTP-ALT-8082
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
8082
Chemin / cible
—
Service
HTTP ALT 8082
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 8008 · HTTP | http | Scan de ports port scan syn · via HTTP:8008 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8008
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=HKHNSlwzHJmeByStlmYfUc5h HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=HKHNSlwzHJmeByStlmYfUc5h HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 9443 · HTTPS | https | Scan de ports port scan syn · via HTTPS:9443 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTPS
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
9443
Chemin / cible
—
Service
HTTPS
Payload
GET http://oracle.vanhoang.id.vn:18451/?nonce=NdnQ816zJcSquxylZqoexDb4 HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 3 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
HTTPS alt 9443 probe
User-Agent
—
Règles WAF
—
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=NdnQ816zJcSquxylZqoexDb4 HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=NdnQ816zJcSquxylZqoexDb4 HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 9002 · HTTP | http | Scan de ports port scan syn · via HTTP:9002 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
9002
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=NENqKXWPxpAF0SDOOq0ZTN-6 HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=NENqKXWPxpAF0SDOOq0ZTN-6 HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8889 · HTTP | http | Scan de ports port scan syn · via HTTP:8889 · (reconnaissance) | Élevée | Moyen · 43 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8889
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 43
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=TZqnP1LVzjUnppc3PW8iglVp HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=TZqnP1LVzjUnppc3PW8iglVp HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8443 · HTTPS | https | Scan de ports port scan syn · via HTTPS:8443 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTPS
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
8443
Chemin / cible
—
Service
HTTPS
Payload
GET http://oracle.vanhoang.id.vn:18451/?nonce=nleH66uGp9lrjOY7dO3O5Tez HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
User-Agent
—
Règles WAF
—
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=nleH66uGp9lrjOY7dO3O5Tez HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=nleH66uGp9lrjOY7dO3O5Tez HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8088 · HTTP | http | Scan de ports port scan syn · via HTTP:8088 · (reconnaissance) | Élevée | Moyen · 44 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8088
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 44
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=qoNcWIXRObUbKPFQokDJQ8xF HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=qoNcWIXRObUbKPFQokDJQ8xF HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8084 · HTTP | http | Scan de ports port scan syn · via HTTP:8084 · (reconnaissance) | Élevée | Moyen · 44 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8084
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 44
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=ij3u02AdAqQooVfHAi82HyKr HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=ij3u02AdAqQooVfHAi82HyKr HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 3128 · HTTP | http | Scan de ports port scan syn · via HTTP:3128 · (reconnaissance) | Élevée | Moyen · 44 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
3128
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 44
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=avP0K1CE5Lv1TonXkbbK9Uij HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=avP0K1CE5Lv1TonXkbbK9Uij HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8082 · HTTP | http | Scan de ports port scan syn · via HTTP:8082 · (reconnaissance) | Élevée | Moyen · 43 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8082
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 43
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=OCi46X289sr9XHw3GYhOFBxC HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=OCi46X289sr9XHw3GYhOFBxC HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 7001 · WEBLOGIC | weblogic | Scan de ports port scan syn · via WEBLOGIC:7001 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
WEBLOGIC
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
7001
Chemin / cible
—
Service
WEBLOGIC
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 3 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 9443 · HTTPS | https | Scan de ports port scan syn · via HTTPS:9443 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTPS
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
9443
Chemin / cible
—
Service
HTTPS
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 4 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
HTTPS alt 9443 probe
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 3128 · SQUID | squid | Scan de ports port scan syn · via SQUID:3128 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
SQUID
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
3128
Chemin / cible
—
Service
SQUID
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 3 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 8443 · HTTPS | https | Scan de ports port scan syn · via HTTPS:8443 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTPS
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
8443
Chemin / cible
—
Service
HTTPS
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 3 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 9002 · MINIO CONSOLE | minio-console | Scan de ports port scan syn · via MINIO CONSOLE:9002 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
MINIO-CONSOLE
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
9002
Chemin / cible
—
Service
MINIO CONSOLE
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 8889 · SPLUNK HEC | splunk-hec | Scan de ports port scan syn · via SPLUNK HEC:8889 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
SPLUNK-HEC
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
8889
Chemin / cible
—
Service
SPLUNK HEC
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 5987 · HTTP | http | Scan de ports port scan syn · via HTTP:5987 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
5987
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=vJ-_5bs9t2LNOJlFw1PGAz8M HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=vJ-_5bs9t2LNOJlFw1PGAz8M HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 5987 · HTTP | http | Scan de ports port scan syn · via HTTP:5987 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
5987
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=znvzw8LqOL_1mH5yV2lrPzKt HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=znvzw8LqOL_1mH5yV2lrPzKt HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8004 · HTTP | http | Scan de ports port scan syn · via HTTP:8004 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8004
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=0BaclhyKaxXDbtwHQGbIJVcf HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=0BaclhyKaxXDbtwHQGbIJVcf HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 9999 · HTTP | http | Scan de ports port scan syn · via HTTP:9999 · (reconnaissance) | Élevée | Moyen · 43 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
9999
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 43
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=KX-Im7AjZYf8mwTcptyDyKut HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=KX-Im7AjZYf8mwTcptyDyKut HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8111 · HTTP | http | Scan de ports port scan syn · via HTTP:8111 · (reconnaissance) | Élevée | Moyen · 43 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8111
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 43
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=nqxjRfSN7howNb87a7h-UL71 HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=nqxjRfSN7howNb87a7h-UL71 HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 5987 · WINRM HTTP | winrm-http | Scan de ports port scan syn · via WINRM HTTP:5987 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
WINRM-HTTP
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
5987
Chemin / cible
—
Service
WINRM HTTP
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 9999 · ADMIN ALT | admin-alt | Scan de ports port scan syn · via ADMIN ALT:9999 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
ADMIN-ALT
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
9999
Chemin / cible
—
Service
ADMIN ALT
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 8111 · HTTP | http | Scan de ports port scan syn · via HTTP:8111 · (reconnaissance) | Élevée | Moyen · 43 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8111
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 43
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=F41a2DM3bCvx_0v7P_xG6mVK HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=F41a2DM3bCvx_0v7P_xG6mVK HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8004 · HTTP | http | Scan de ports port scan syn · via HTTP:8004 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
8004
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=6UZsiVZhtnXvur7Mez43c6R3 HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=6UZsiVZhtnXvur7Mez43c6R3 HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 9999 · HTTP | http | Scan de ports port scan syn · via HTTP:9999 · (reconnaissance) | Élevée | Moyen · 43 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Go-http-client/1.1
Émulateur
HTTP
WAF
10
Recommandation
Surveiller
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
9999
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 43
Confiance : Confiance 100 % — 2 tag(s) WAF
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Go-http-client/1.1
Règles WAF
rce-14
sap-sapcontrol-path
Payload (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=Dbu-6UenyyF1NGe_u3C948Zp HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent:
Requête brute (extrait)
GET http://oracle.vanhoang.id.vn:18451/?nonce=Dbu-6UenyyF1NGe_u3C948Zp HTTP/1.1 Host: oracle.vanhoang.id.vn:18451 User-Agent: Go-http-client/1.1 Accept: application/json Accept-Encoding: gzip Connection: close |
|||||||
| TCP | 8004 · HTTP ALT 8004 | http-alt-8004 | Scan de ports port scan syn · via HTTP ALT 8004:8004 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTP-ALT-8004
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
8004
Chemin / cible
—
Service
HTTP ALT 8004
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 8111 · TEAMCITY | teamcity | Scan de ports port scan syn · via TEAMCITY:8111 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
TEAMCITY
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
8111
Chemin / cible
—
Service
TEAMCITY
Payload
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 4 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
Minecraft varint handshake
SOCKS5 greeting
User-Agent
—
Règles WAF
—
Payload (extrait)
|
|||||||
| TCP | 8443 · HTTPS | https | Scan de ports port scan syn · via HTTPS:8443 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTPS
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
8443
Chemin / cible
—
Service
HTTPS
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
User-Agent
—
Règles WAF
—
|
|||||||
| TCP | 9999 · ADMIN ALT | admin-alt | Scan de ports port scan syn · via ADMIN ALT:9999 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
ADMIN-ALT
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
9999
Chemin / cible
—
Service
ADMIN ALT
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 1 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
User-Agent
—
Règles WAF
—
|
|||||||
| TCP | 8084 · HTTP ALT 8084 | http-alt-8084 | Scan de ports port scan syn · via HTTP ALT 8084:8084 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTP-ALT-8084
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
8084
Chemin / cible
—
Service
HTTP ALT 8084
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 1 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
User-Agent
—
Règles WAF
—
|
|||||||
| TCP | 9443 · HTTPS | https | Scan de ports port scan syn · via HTTPS:9443 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTPS
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
9443
Chemin / cible
—
Service
HTTPS
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 2 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
HTTPS alt 9443 probe
User-Agent
—
Règles WAF
—
|
|||||||
| TCP | 8004 · HTTP ALT 8004 | http-alt-8004 | Scan de ports port scan syn · via HTTP ALT 8004:8004 · (reconnaissance) | Élevée | Moyen · 42 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
Émulateur
HTTP-ALT-8004
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
8004
Chemin / cible
—
Service
HTTP ALT 8004
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +18
Risque capteur
Moyen
· 42
Confiance : Confiance 100 % — 1 signal(aux) capteur
Protocole émulé
1
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
User-Agent
—
Règles WAF
—
|
|||||||