{"ip":"112.97.78.176","exported_at":"2026-06-19T22:56:25+00:00","period_days":1,"metrics":{"events7d":1,"distinct_ports":1,"distinct_classifications":1,"max_severity":6,"last_sensor_id":"paris-1","max_waf_score":null,"max_risk_score":38,"attack_stage":"probe","attack_chain_stage":"discovery","threat_family":["ics_probe"],"recommended_action":"monitor","confidence":1,"risk_breakdown":{"waf":8,"classification":58,"behavior":0,"geo":0,"protocol":30,"novelty":0},"mitre_tactics":["TA0007","TA0001"],"mitre_technique":"T0836","top_mitre_technique":"T0836","top_mitre_count":1,"executive_one_liner_fr":"Activit\u00e9 suspecte \u00b7 risque 38\/100","campaign_hint_fr":null,"confidence_breakdown":{"waf":8,"classification":58,"behavior":0,"geo":0,"protocol":30,"novelty":0,"risk_score":38},"persona_hostname":"mail.sensor-1.internal","correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":100,"confidence_hint_fr":null,"sensor_role_label_fr":"Renseignement menaces","tags_summary_labels_fr":["Ot Dnp3 Unauth","Ot Dnp3 Variants","Upstream"],"tags_summary":["INT-OT-dnp3-unauth","INT-OT-dnp3-variants","INT-upstream"],"attack_vector":"dnp3 probe \u00b7 via DNP3 TCP:20000 \u00b7 (sonde \/ probe)","protocol_details":{"dnp3_probe_fr":"Sonde DNP3 (SCADA \u00e9nergie)","payload_preview":"\u0005\u0001\u0000","port":20000,"service":"dnp3-tcp","service_label_fr":"DNP3 TCP"},"protocol_summary_fr":"Payload \u0005\u0001 \u00b7 DNP3 TCP:20000","evidence_snippet":"\u0005\u0001","target_port_label":"20000 \u00b7 DNP3 TCP","emulator_service":"dnp3-tcp","confidence_reason":"Confiance 100 % \u2014 4 signal(aux) capteur","classification_reason":"Type \u00ab dnp3_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%","classification_reason_label_fr":"Type \u00ab dnp3_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%","confidence_factors_fr":"Confiance 100 % \u2014 Score WAF 8","payload_preview":"\u0005\u0001"},"events":[],"total_events":0}