{"ip":"165.154.40.205","exported_at":"2026-06-20T07:18:44+00:00","period_days":30,"metrics":{"events7d":85,"distinct_ports":4,"distinct_classifications":24,"max_severity":7,"last_sensor_id":"paris-1","max_waf_score":6,"max_risk_score":87,"attack_stage":"probe","attack_chain_stage":"discovery","threat_family":["disclosed_scanner","cloud_metadata_scan"],"recommended_action":"monitor","confidence":0.5,"risk_breakdown":{"waf":8,"classification":45,"behavior":0,"geo":0,"protocol":30,"novelty":0},"mitre_tactics":["TA0007","TA0001"],"mitre_technique":"TA0007","top_mitre_technique":"TA0007","top_mitre_count":79,"executive_one_liner_fr":"Activit\u00e9 suspecte \u00b7 risque 45\/100","campaign_hint_fr":null,"confidence_breakdown":{"waf":8,"classification":45,"behavior":0,"geo":0,"protocol":30,"novelty":0,"risk_score":45},"persona_hostname":"mail.sensor-1.internal","correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":50,"confidence_hint_fr":"Confiance mod\u00e9r\u00e9e \u2014 signal unique","sensor_role_label_fr":"Renseignement menaces","tags_summary_labels_fr":["pat-0554"],"tags_summary":["pat-0554"],"attack_vector":"cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)","protocol_details":{"payload_preview":"CNXN\u0000\u0000\u0000\u0001\u0000\u0010\u0000\u0000\u0007\u0000\u0000\u00002\u0002\u0000\u0000\ufffd\ufffd\ufffd\ufffdhost::\u0000","port":4567,"service":"aws-ecs-agent","service_label_fr":"AWS ECS AGENT"},"protocol_summary_fr":"Payload CNXN\u0000\u0000\u0000\u0001\u0000\u0010\u0000\u0000\u0007\u0000\u0000\u00002\u0002\u0000\u0000\ufffd\ufffd\ufffd\ufffdhost:: \u00b7 AWS ECS AGENT:4567","evidence_snippet":"CNXN2\ufffd\ufffd\ufffd\ufffdhost::","target_port_label":"4567 \u00b7 AWS ECS AGENT","emulator_service":"aws-ecs-agent","confidence_reason":"Confiance 50 % \u2014 Motif catalogue confirm\u00e9","classification_reason":"Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%","classification_reason_label_fr":"Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%","confidence_factors_fr":"Confiance 50 % \u2014 Score WAF 8","payload_preview":"CNXN2\ufffd\ufffd\ufffd\ufffdhost::"},"events":[{"id":9631872,"ip":"165.154.40.205","ts":"2026-06-19 04:15:22.000000","proto":"tcp","src_port":52694,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 31, \u0022payload_entropy\u0022: 3.3729205036561045, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0554\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00222ab0510cc4156c41c24112bc2a720db2\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022CNXN\\u0000\\u0000\\u0000\\u0001\\u0000\\u0010\\u0000\\u0000\\u0007\\u0000\\u0000\\u00002\\u0002\\u0000\\u0000\ufffd\ufffd\ufffd\ufffdhost::\\u0000\u0022, \u0022request_sample\u0022: \u0022CNXN\\u0000\\u0000\\u0000\\u0001\\u0000\\u0010\\u0000\\u0000\\u0007\\u0000\\u0000\\u00002\\u0002\\u0000\\u0000\ufffd\ufffd\ufffd\ufffdhost::\\u0000\u0022, \u0022payload_snippet\u0022: \u0022CNXN\\u0000\\u0000\\u0000\\u0001\\u0000\\u0010\\u0000\\u0000\\u0007\\u0000\\u0000\\u00002\\u0002\\u0000\\u0000\ufffd\ufffd\ufffd\ufffdhost::\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022CNXN\\u0000\\u0000\\u0000\\u0001\\u0000\\u0010\\u0000\\u0000\\u0007\\u0000\\u0000\\u00002\\u0002\\u0000\\u0000\ufffd\ufffd\ufffd\ufffdhost::\\u0000\u0022, \u0022payload_snippet\u0022: \u0022CNXN\\u0000\\u0000\\u0000\\u0001\\u0000\\u0010\\u0000\\u0000\\u0007\\u0000\\u0000\\u00002\\u0002\\u0000\\u0000\ufffd\ufffd\ufffd\ufffdhost::\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022b565534e69f6d2d92f88322b47345e813f5bad2e\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022CNXN\\u0000\\u0000\\u0000\\u0001\\u0000\\u0010\\u0000\\u0000\\u0007\\u0000\\u0000\\u00002\\u0002\\u0000\\u0000\ufffd\ufffd\ufffd\ufffdhost::\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022CNXN2\ufffd\ufffd\ufffd\ufffdhost::\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0554\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0554\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022CNXN\\u0000\\u0000\\u0000\\u0001\\u0000\\u0010\\u0000\\u0000\\u0007\\u0000\\u0000\\u00002\\u0002\\u0000\\u0000\ufffd\ufffd\ufffd\ufffdhost::\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022CNXN2\ufffd\ufffd\ufffd\ufffdhost::\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":31},{"id":9631870,"ip":"165.154.40.205","ts":"2026-06-19 04:15:19.000000","proto":"tcp","src_port":51860,"dst_port":4567,"service":"aws-ecs-agent","classification":"mqtt_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 18, \u0022payload_entropy\u0022: 3.4193819456463714, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 54.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 54.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 49, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022d6b7341b13604b8794bd14cb80451391909c14d8\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mqtt_probe \u00bb (signaux protocolaires) \u00b7 confiance 97%\u0022, \u0022confidence\u0022: 0.97, \u0022classification_confidence\u0022: 0.97, \u0022precision_score\u0022: 110, \u0022precision_signals\u0022: [\u0022pat-0373\u0022, \u0022pat-0615\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0373\u0022, \u0022pat-0615\u0022], \u0022matched_patterns\u0022: [\u0022pat-0373\u0022, \u0022pat-0448\u0022, \u0022pat-0543\u0022, \u0022pat-0615\u0022, \u0022pat-0554\u0022], \u0022matched_pattern_names\u0022: [\u0022MQTT protocol\u0022, \u0022UA nmap\u0022, \u0022Sigma nmap UA\u0022, \u0022MQTT alt CONNECT\u0022, \u0022Minecraft varint handshake\u0022], \u0022pattern_ids\u0022: [\u0022pat-0373\u0022, \u0022pat-0448\u0022, \u0022pat-0543\u0022, \u0022pat-0615\u0022, \u0022pat-0554\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 54.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 49}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 97.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022ad60b419f2f0103bea99389955f5bdf8\u0022, \u0022path_pattern_hash\u0022: \u00224449b927317468afa12a2f935a413459\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 49}, \u0022payload_preview\u0022: \u0022\\u0010\\u0010\\u0000\\u0004MQTT\\u0004\\u0002\\u0000\\u001e\\u0000\\u0004nmap\u0022, \u0022request_sample\u0022: \u0022\\u0010\\u0010\\u0000\\u0004MQTT\\u0004\\u0002\\u0000\\u001e\\u0000\\u0004nmap\u0022, \u0022payload_snippet\u0022: \u0022\\u0010\\u0010\\u0000\\u0004MQTT\\u0004\\u0002\\u0000\\u001e\\u0000\\u0004nmap\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0010\\u0010\\u0000\\u0004MQTT\\u0004\\u0002\\u0000\\u001e\\u0000\\u0004nmap\u0022, \u0022payload_snippet\u0022: \u0022\\u0010\\u0010\\u0000\\u0004MQTT\\u0004\\u0002\\u0000\\u001e\\u0000\\u0004nmap\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mqtt_probe \u00bb (signaux protocolaires) \u00b7 confiance 97%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002224798a3f7723697a1fb1b67adfcaf10c30ef518b\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0010\\u0010\\u0000\\u0004MQTT\\u0004\\u0002\\u0000\\u001e\\u0000\\u0004nmap\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022MQTTnmap\u0022, \u0022attack_vector\u0022: \u0022mqtt probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 97 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab mqtt_probe \u00bb (signaux protocolaires) \u00b7 confiance 97%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab mqtt_probe \u00bb (signaux protocolaires) \u00b7 confiance 97%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 49\/100\u0022, \u0022confidence_pct\u0022: 97, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 54.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 49}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 49, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0373\u0022, \u0022pat-0615\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0373\u0022, \u0022pat-0615\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0010\\u0010\\u0000\\u0004MQTT\\u0004\\u0002\\u0000\\u001e\\u0000\\u0004nmap\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022mqtt probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022MQTTnmap\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 97 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 97 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022mqtt_connect\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022mqtt_connect\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":18},{"id":9631866,"ip":"165.154.40.205","ts":"2026-06-19 04:15:16.000000","proto":"tcp","src_port":51232,"dst_port":4567,"service":"aws-ecs-agent","classification":"websphere_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 48, \u0022payload_entropy\u0022: 2.5723387961875535, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 54.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 54.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab websphere_probe \u00bb (signaux protocolaires) \u00b7 confiance 47%\u0022, \u0022confidence\u0022: 0.47, \u0022classification_confidence\u0022: 0.47, \u0022precision_score\u0022: 56, \u0022precision_signals\u0022: [\u0022pat-0605\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0605\u0022], \u0022matched_patterns\u0022: [\u0022pat-0605\u0022, \u0022pat-0768\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022GIOP WebSphere IIOP\u0022, \u0022Mumble ping\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0605\u0022, \u0022pat-0768\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 54.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 47.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022a2295e3d24182f08220a2dae2c40ff1c\u0022, \u0022path_pattern_hash\u0022: \u0022a8ef247ba3612b90c1c670387b185e85\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022GIOP\\u0001\\u0000\\u0001\\u0000$\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0006\\u0000\\u0000\\u0000abcdef\\u0000\\u0000\\u0004\\u0000\\u0000\\u0000get\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022request_sample\u0022: \u0022GIOP\\u0001\\u0000\\u0001\\u0000$\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0006\\u0000\\u0000\\u0000abcdef\\u0000\\u0000\\u0004\\u0000\\u0000\\u0000get\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022GIOP\\u0001\\u0000\\u0001\\u0000$\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0006\\u0000\\u0000\\u0000abcdef\\u0000\\u0000\\u0004\\u0000\\u0000\\u0000get\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GIOP\\u0001\\u0000\\u0001\\u0000$\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0006\\u0000\\u0000\\u0000abcdef\\u0000\\u0000\\u0004\\u0000\\u0000\\u0000get\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022GIOP\\u0001\\u0000\\u0001\\u0000$\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0006\\u0000\\u0000\\u0000abcdef\\u0000\\u0000\\u0004\\u0000\\u0000\\u0000get\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab websphere_probe \u00bb (signaux protocolaires) \u00b7 confiance 47%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022enterprise_scan\u0022, \u0022enterprise_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022529cd784f1410c3501f5b512ee6a7686eb39c511\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GIOP\\u0001\\u0000\\u0001\\u0000$\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0006\\u0000\\u0000\\u0000abcdef\\u0000\\u0000\\u0004\\u0000\\u0000\\u0000get\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022GIOP$abcdefget\u0022, \u0022attack_vector\u0022: \u0022websphere probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 47 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab websphere_probe \u00bb (signaux protocolaires) \u00b7 confiance 47%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab websphere_probe \u00bb (signaux protocolaires) \u00b7 confiance 47%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 47, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 54.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0605\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0605\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GIOP\\u0001\\u0000\\u0001\\u0000$\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0006\\u0000\\u0000\\u0000abcdef\\u0000\\u0000\\u0004\\u0000\\u0000\\u0000get\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022websphere probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022GIOP$abcdefget\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 47 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 47 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":48},{"id":9631859,"ip":"165.154.40.205","ts":"2026-06-19 04:15:13.000000","proto":"tcp","src_port":50460,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 2, \u0022payload_entropy\u0022: 1.0, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 34, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 34}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00224b24f4cca7e61459da3fb7bee3042b66\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 34}, \u0022payload_preview\u0022: \u0022\ufffd\\u0001\u0022, \u0022request_sample\u0022: \u0022\ufffd\\u0001\u0022, \u0022payload_snippet\u0022: \u0022\ufffd\\u0001\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\ufffd\\u0001\u0022, \u0022payload_snippet\u0022: \u0022\ufffd\\u0001\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022f9bc02d88cef6a77b4ff33b5b46697d5b54f5286\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\ufffd\\u0001\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 3 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 34\/100\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 34}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 34, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\ufffd\\u0001\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 3 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":2},{"id":9631858,"ip":"165.154.40.205","ts":"2026-06-19 04:15:10.000000","proto":"tcp","src_port":49866,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 14, \u0022payload_entropy\u0022: 3.128085278891395, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 34, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022matched_patterns\u0022: [\u0022pat-0411\u0022], \u0022matched_pattern_names\u0022: [\u0022Redis INFO\u0022], \u0022pattern_ids\u0022: [\u0022pat-0411\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 34}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00224f9ff4b8ec8624803229b3cea88426af\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 34}, \u0022payload_preview\u0022: \u0022*1\\r\\n$4\\r\\ninfo\\r\\n\u0022, \u0022request_sample\u0022: \u0022*1\\r\\n$4\\r\\ninfo\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022*1\\r\\n$4\\r\\ninfo\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022*1\\r\\n$4\\r\\ninfo\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022*1\\r\\n$4\\r\\ninfo\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022d6d9b74d2818c08f4e51c3b42cdf29062ed25474\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022*1\\r\\n$4\\r\\ninfo\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022*1\\r\\n$4\\r\\ninfo\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 3 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 34\/100\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 34}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 34, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022*1\\r\\n$4\\r\\ninfo\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022*1\\r\\n$4\\r\\ninfo\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 3 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":14},{"id":9631854,"ip":"165.154.40.205","ts":"2026-06-19 04:15:07.000000","proto":"tcp","src_port":49132,"dst_port":4567,"service":"aws-ecs-agent","classification":"mssql_tds","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 65, \u0022payload_entropy\u0022: 3.3778795428324466, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 56.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 32, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0356\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0356\u0022], \u0022matched_patterns\u0022: [\u0022pat-0356\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022MSSQL TDS prelogin\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0356\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 32}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022bf7469d78bb1798d5188209f4494c1a3\u0022, \u0022path_pattern_hash\u0022: \u0022285321e27377a1f85e5a231ca6cbffb2\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 32}, \u0022payload_preview\u0022: \u0022A\\u0000\\u0000\\u0000:0\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000test.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u001b\\u0000\\u0000\\u0000\\u0001serverStatus\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd?\\u0000\u0022, \u0022request_sample\u0022: \u0022A\\u0000\\u0000\\u0000:0\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000test.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u001b\\u0000\\u0000\\u0000\\u0001serverStatus\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd?\\u0000\u0022, \u0022payload_snippet\u0022: \u0022A\\u0000\\u0000\\u0000:0\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000test.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u001b\\u0000\\u0000\\u0000\\u0001serverStatus\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd?\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022A\\u0000\\u0000\\u0000:0\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000test.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u001b\\u0000\\u0000\\u0000\\u0001serverStatus\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd?\\u0000\u0022, \u0022payload_snippet\u0022: \u0022A\\u0000\\u0000\\u0000:0\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000test.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u001b\\u0000\\u0000\\u0000\\u0001serverStatus\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd?\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022fc082cf444b11c7db849fc3789a6e5257d63c512\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022A\\u0000\\u0000\\u0000:0\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000test.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u001b\\u0000\\u0000\\u0000\\u0001serverStatus\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd?\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022A:0\ufffd\ufffd\ufffd\ufffd\ufffdtest.$cmd\ufffd\ufffd\ufffd\ufffdserverStatus\ufffd?\u0022, \u0022attack_vector\u0022: \u0022mssql tds \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 32\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 32}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 32, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0356\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0356\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022A\\u0000\\u0000\\u0000:0\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000test.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u001b\\u0000\\u0000\\u0000\\u0001serverStatus\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd?\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022mssql tds \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022A:0\ufffd\ufffd\ufffd\ufffd\ufffdtest.$cmd\ufffd\ufffd\ufffd\ufffdserverStatus\ufffd?\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":65},{"id":9631849,"ip":"165.154.40.205","ts":"2026-06-19 04:15:04.000000","proto":"tcp","src_port":48522,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 18, \u0022payload_entropy\u0022: 1.2086489509530647, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0532\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022817773a4a3987fc7642ff30928d792fc\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\\u0000\\u0003\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000\\u0000\\u0000\\u000f\\u0000\u0022, \u0022request_sample\u0022: \u0022\\u0000\\u0003\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000\\u0000\\u0000\\u000f\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\\u0003\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000\\u0000\\u0000\\u000f\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0000\\u0003\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000\\u0000\\u0000\\u000f\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\\u0003\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000\\u0000\\u0000\\u000f\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002268445e2602ed716dd4f236fcd7fb2f65aea6a97e\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\\u0003\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000\\u0000\\u0000\\u000f\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0532\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0532\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\\u0003\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000\\u0000\\u0000\\u000f\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: null, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":18},{"id":9631844,"ip":"165.154.40.205","ts":"2026-06-19 04:15:01.000000","proto":"tcp","src_port":47836,"dst_port":4567,"service":"aws-ecs-agent","classification":"port_4567_tcp","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 450, \u0022payload_entropy\u0022: 1.82286057779224, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 38.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 38.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 41, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00222215644c8557ed6e2203af7892fac04e432acbb1\u0022, \u0022event_fingerprint\u0022: \u00223438e26e87237863cb28a15a34aea0c25dcaba2f\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_4567_tcp \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0348\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0348\u0022], \u0022matched_patterns\u0022: [\u0022pat-0348\u0022, \u0022pat-0868\u0022, \u0022pat-0532\u0022, \u0022pat-0577\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022RDP TPKT header\u0022, \u0022ET H.323 setup\u0022, \u0022NFS RPC mount\u0022, \u0022RADIUS Access-Request\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0348\u0022, \u0022pat-0868\u0022, \u0022pat-0532\u0022, \u0022pat-0577\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 38.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 41}, \u0022named_classification_skipped\u0022: true, \u0022named_candidate\u0022: \u0022rdp_probe\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022eceedace3cdd6b7c3a4b6f3b21c20f1b\u0022, \u0022path_pattern_hash\u0022: \u0022f864580abc1c51fefa22b7b9a4b84104\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 41}, \u0022payload_snippet\u0022: \u0022\\u0001\ufffd\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000\ufffd\\u0001\\u0000\\u0000SQLDB2RA\\u0000\\u0001\\u0000\\u0000\\u0004\\u0001\\u0001\\u0000\\u0005\\u0000\\u001d\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\t\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\t\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\b\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000@\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0001\ufffd\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000\ufffd\\u0001\\u0000\\u0000SQLDB2RA\\u0000\\u0001\\u0000\\u0000\\u0004\\u0001\\u0001\\u0000\\u0005\\u0000\\u001d\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\t\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\t\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\b\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000@\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0003\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\b\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0010\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\u0010\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\ufffd\u0022, \u0022payload_snippet\u0022: \u0022\\u0001\ufffd\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000\ufffd\\u0001\\u0000\\u0000SQLDB2RA\\u0000\\u0001\\u0000\\u0000\\u0004\\u0001\\u0001\\u0000\\u0005\\u0000\\u001d\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\t\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\t\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\b\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000@\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_4567_tcp \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002263b9d23fe59c3302b19d1d395c840dd366940ab3\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0001\ufffd\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000\ufffd\\u0001\\u0000\\u0000SQLDB2RA\\u0000\\u0001\\u0000\\u0000\\u0004\\u0001\\u0001\\u0000\\u0005\\u0000\\u001d\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\t\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\t\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\b\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000@\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffdSQLDB2RA\ufffd\ufffd\\t@\\t@@@@@@@\u0022, \u0022attack_vector\u0022: \u0022port 4567 tcp \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9 \u00b7 Classification nomm\u00e9e non retenue \u2014 preuves insuffisantes\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab port_4567_tcp \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab port_4567_tcp \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 41\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 38.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 41}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 41, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0348\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0348\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0001\ufffd\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000\ufffd\\u0001\\u0000\\u0000SQLDB2RA\\u0000\\u0001\\u0000\\u0000\\u0004\\u0001\\u0001\\u0000\\u0005\\u0000\\u001d\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0001\\t\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\t\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\b\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000@\\u0000\\u0000\\u0000@\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\\u0004\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000@\\u0000\\u0000\\u0000\\u0001\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022port 4567 tcp \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffdSQLDB2RA\ufffd\ufffd\\t@\\t@@@@@@@\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9 \u00b7 Classification nomm\u00e9e non retenue \u2014 preuves insuffisantes\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022meta_truncated\u0022: true, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022db2_probe\u0022, \u0022net_db2_probe\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022db2_probe\u0022, \u0022net_db2_probe\u0022]","anomalies":"[]","severity":5,"bytes_in":450},{"id":9631842,"ip":"165.154.40.205","ts":"2026-06-19 04:14:58.000000","proto":"tcp","src_port":45902,"dst_port":4567,"service":"aws-ecs-agent","classification":"memcached_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 7, \u0022payload_entropy\u0022: 2.2359263506290326, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 52.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 52.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 50, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab memcached_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 164, \u0022precision_signals\u0022: [\u0022pat-0374\u0022, \u0022pat-0533\u0022, \u0022pat-0865\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0374\u0022, \u0022pat-0533\u0022, \u0022pat-0865\u0022], \u0022matched_patterns\u0022: [\u0022pat-0374\u0022, \u0022pat-0533\u0022, \u0022pat-0865\u0022], \u0022matched_pattern_names\u0022: [\u0022Memcached stats\u0022, \u0022Memcached stats\u0022, \u0022ET Memcached UDP\u0022], \u0022pattern_ids\u0022: [\u0022pat-0374\u0022, \u0022pat-0533\u0022, \u0022pat-0865\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 52.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 50}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002211e629574907d3a9ced402e26f4a98df\u0022, \u0022path_pattern_hash\u0022: \u0022549d36783f9e3c43618e715d78a40b3b\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 50}, \u0022payload_preview\u0022: \u0022stats\\r\\n\u0022, \u0022request_sample\u0022: \u0022stats\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022stats\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022stats\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022stats\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab memcached_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022investigate\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022f951cf06034c1c77568af59934e70903d3996f23\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022stats\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022stats\u0022, \u0022attack_vector\u0022: \u0022memcached probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab memcached_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab memcached_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 50\/100 (Moyen) \u2014 MITRE TA0007 \u2014 confiance 100 % \u2014 via AWS ECS AGENT\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 52.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 50}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 50, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0374\u0022, \u0022pat-0533\u0022, \u0022pat-0865\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0374\u0022, \u0022pat-0533\u0022, \u0022pat-0865\u0022], \u0022recommended_action\u0022: \u0022investigate\u0022, \u0022recommended_action_label\u0022: \u0022Investiguer\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022stats\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022memcached probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022stats\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_investigate\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022], \u0022behavior_alert_count\u0022: 1, \u0022behavior_priority\u0022: 72}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":7},{"id":9631838,"ip":"165.154.40.205","ts":"2026-06-19 04:14:54.000000","proto":"tcp","src_port":45160,"dst_port":4567,"service":"aws-ecs-agent","classification":"mssql_tds","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 52, \u0022payload_entropy\u0022: 3.604409845438833, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 56.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002276e3eec12032c48bbcad7893ab71523e54e5605a\u0022, \u0022event_fingerprint\u0022: \u0022b0d3fdd8f53738446ea599c55dda69e3d88716a2\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 95%\u0022, \u0022confidence\u0022: 0.95, \u0022classification_confidence\u0022: 0.95, \u0022precision_score\u0022: 83, \u0022precision_signals\u0022: [\u0022pat-0519\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0519\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0519\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022MSSQL TDS prelogin\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0519\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 35}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 95.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002223edc99bdfe5fe902f5ff28aa98ef130\u0022, \u0022path_pattern_hash\u0022: \u0022285321e27377a1f85e5a231ca6cbffb2\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 35}, \u0022payload_preview\u0022: \u0022\\u0012\\u0001\\u00004\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0015\\u0000\\u0006\\u0001\\u0000\\u001b\\u0000\\u0001\\u0002\\u0000\\u001c\\u0000\\f\\u0003\\u0000(\\u0000\\u0004\ufffd\\b\\u0000\\u0001U\\u0000\\u0000\\u0000MSSQLServer\\u0000H\\u000f\\u0000\\u0000\u0022, \u0022request_sample\u0022: \u0022\\u0012\\u0001\\u00004\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0015\\u0000\\u0006\\u0001\\u0000\\u001b\\u0000\\u0001\\u0002\\u0000\\u001c\\u0000\\f\\u0003\\u0000(\\u0000\\u0004\ufffd\\b\\u0000\\u0001U\\u0000\\u0000\\u0000MSSQLServer\\u0000H\\u000f\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0012\\u0001\\u00004\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0015\\u0000\\u0006\\u0001\\u0000\\u001b\\u0000\\u0001\\u0002\\u0000\\u001c\\u0000\\f\\u0003\\u0000(\\u0000\\u0004\ufffd\\b\\u0000\\u0001U\\u0000\\u0000\\u0000MSSQLServer\\u0000H\\u000f\\u0000\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0012\\u0001\\u00004\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0015\\u0000\\u0006\\u0001\\u0000\\u001b\\u0000\\u0001\\u0002\\u0000\\u001c\\u0000\\f\\u0003\\u0000(\\u0000\\u0004\ufffd\\b\\u0000\\u0001U\\u0000\\u0000\\u0000MSSQLServer\\u0000H\\u000f\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0012\\u0001\\u00004\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0015\\u0000\\u0006\\u0001\\u0000\\u001b\\u0000\\u0001\\u0002\\u0000\\u001c\\u0000\\f\\u0003\\u0000(\\u0000\\u0004\ufffd\\b\\u0000\\u0001U\\u0000\\u0000\\u0000MSSQLServer\\u0000H\\u000f\\u0000\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 95%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022a186c151565598916d143cbaa1053cfbfc632e77\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0012\\u0001\\u00004\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0015\\u0000\\u0006\\u0001\\u0000\\u001b\\u0000\\u0001\\u0002\\u0000\\u001c\\u0000\\f\\u0003\\u0000(\\u0000\\u0004\ufffd\\b\\u0000\\u0001U\\u0000\\u0000\\u0000MSSQLServer\\u0000H\\u000f\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u00224(\ufffdUMSSQLServerH\u0022, \u0022attack_vector\u0022: \u0022mssql tds \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 95 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 95%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 95%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 35\/100\u0022, \u0022confidence_pct\u0022: 95, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 35}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 35, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0519\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0519\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0012\\u0001\\u00004\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0015\\u0000\\u0006\\u0001\\u0000\\u001b\\u0000\\u0001\\u0002\\u0000\\u001c\\u0000\\f\\u0003\\u0000(\\u0000\\u0004\ufffd\\b\\u0000\\u0001U\\u0000\\u0000\\u0000MSSQLServer\\u0000H\\u000f\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022mssql tds \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u00224(\ufffdUMSSQLServerH\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 95 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 95 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022mssql_tds\u0022, \u0022net_mssql_tds\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022mssql_tds\u0022, \u0022net_mssql_tds\u0022]","anomalies":"[]","severity":5,"bytes_in":52},{"id":9631836,"ip":"165.154.40.205","ts":"2026-06-19 04:14:51.000000","proto":"tcp","src_port":44444,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 13, \u0022payload_entropy\u0022: 2.7773627950641693, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022ca37a1c00de5b06d075c03b89c23ee0359ee53fa\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0554\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00222167ce4c1a0201b2283cc57c40a74bac\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\\u0004\\u0001\\u0000\\u0016\\u0000\\u0000\\u0001root\\u0000\u0022, \u0022request_sample\u0022: \u0022\\u0004\\u0001\\u0000\\u0016\\u0000\\u0000\\u0001root\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0004\\u0001\\u0000\\u0016\\u0000\\u0000\\u0001root\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0004\\u0001\\u0000\\u0016\\u0000\\u0000\\u0001root\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0004\\u0001\\u0000\\u0016\\u0000\\u0000\\u0001root\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00224c397c2b35fed1574f0ae8eb9f1eb4cfd62cc22c\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0004\\u0001\\u0000\\u0016\\u0000\\u0000\\u0001root\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022root\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0554\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0554\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0004\\u0001\\u0000\\u0016\\u0000\\u0000\\u0001root\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022root\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022, \u0022socks4_greeting\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022, \u0022socks4_greeting\u0022]","anomalies":"[]","severity":5,"bytes_in":13},{"id":9631835,"ip":"165.154.40.205","ts":"2026-06-19 04:14:48.000000","proto":"tcp","src_port":43476,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 41, \u0022payload_entropy\u0022: 4.503416638553355, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0567\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022d345b721f5d98a2b04db9dadef49f152\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\\u0005\\u0004\\u0000\\u0001\\u0002\ufffd\\u0005\\u0001\\u0000\\u0003\\ngoogle.com\\u0000PGET \/ HTTP\/1.0\\r\\n\\r\\n\u0022, \u0022request_sample\u0022: \u0022\\u0005\\u0004\\u0000\\u0001\\u0002\ufffd\\u0005\\u0001\\u0000\\u0003\\ngoogle.com\\u0000PGET \/ HTTP\/1.0\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022\\u0005\\u0004\\u0000\\u0001\\u0002\ufffd\\u0005\\u0001\\u0000\\u0003\\ngoogle.com\\u0000PGET \/ HTTP\/1.0\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0005\\u0004\\u0000\\u0001\\u0002\ufffd\\u0005\\u0001\\u0000\\u0003\\ngoogle.com\\u0000PGET \/ HTTP\/1.0\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022\\u0005\\u0004\\u0000\\u0001\\u0002\ufffd\\u0005\\u0001\\u0000\\u0003\\ngoogle.com\\u0000PGET \/ HTTP\/1.0\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022aa2df78bf8b516b949143fa37416cfdba6078c04\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0005\\u0004\\u0000\\u0001\\u0002\ufffd\\u0005\\u0001\\u0000\\u0003\\ngoogle.com\\u0000PGET \/ HTTP\/1.0\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd\\ngoogle.comPGET \/ HTTP\/1.0\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0567\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0567\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0005\\u0004\\u0000\\u0001\\u0002\ufffd\\u0005\\u0001\\u0000\\u0003\\ngoogle.com\\u0000PGET \/ HTTP\/1.0\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd\\ngoogle.comPGET \/ HTTP\/1.0\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":41},{"id":9631831,"ip":"165.154.40.205","ts":"2026-06-19 04:14:45.000000","proto":"tcp","src_port":42240,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 90, \u0022payload_entropy\u0022: 3.5636982611044665, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0771\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022ee3f9a4a2b04c32e4d515a179936da49\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\\u0000Z\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u00016\\u0001,\\u0000\\u0000\\b\\u0000\ufffd\\b\\u0000\\u0000\\u0000\\u0001\\u0000 \\u0000:\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u00004\ufffd\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000(CONNECT_DATA=(COMMAND=version))\u0022, \u0022request_sample\u0022: \u0022\\u0000Z\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u00016\\u0001,\\u0000\\u0000\\b\\u0000\ufffd\\b\\u0000\\u0000\\u0000\\u0001\\u0000 \\u0000:\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u00004\ufffd\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000(CONNECT_DATA=(COMMAND=version))\u0022, \u0022payload_snippet\u0022: \u0022\\u0000Z\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u00016\\u0001,\\u0000\\u0000\\b\\u0000\ufffd\\b\\u0000\\u0000\\u0000\\u0001\\u0000 \\u0000:\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u00004\ufffd\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000(CONNECT_DATA=(COMMAND=version))\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0000Z\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u00016\\u0001,\\u0000\\u0000\\b\\u0000\ufffd\\b\\u0000\\u0000\\u0000\\u0001\\u0000 \\u0000:\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u00004\ufffd\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000(CONNECT_DATA=(COMMAND=version))\u0022, \u0022payload_snippet\u0022: \u0022\\u0000Z\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u00016\\u0001,\\u0000\\u0000\\b\\u0000\ufffd\\b\\u0000\\u0000\\u0000\\u0001\\u0000 \\u0000:\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u00004\ufffd\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000(CONNECT_DATA=(COMMAND=version))\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002217f4f1f4ee641863cbd6047880791fcc2dfc77b1\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000Z\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u00016\\u0001,\\u0000\\u0000\\b\\u0000\ufffd\\b\\u0000\\u0000\\u0000\\u0001\\u0000 \\u0000:\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u00004\ufffd\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000(CONNECT_DATA=(COMMAND=version))\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022Z6,\ufffd :4\ufffd(CONNECT_DATA=(COMMAND=version))\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0771\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0771\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000Z\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u00016\\u0001,\\u0000\\u0000\\b\\u0000\ufffd\\b\\u0000\\u0000\\u0000\\u0001\\u0000 \\u0000:\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u00004\ufffd\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000(CONNECT_DATA=(COMMAND=version))\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022Z6,\ufffd :4\ufffd(CONNECT_DATA=(COMMAND=version))\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":90},{"id":9631827,"ip":"165.154.40.205","ts":"2026-06-19 04:14:42.000000","proto":"tcp","src_port":41010,"dst_port":4567,"service":"aws-ecs-agent","classification":"kafka_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 175, \u0022payload_entropy\u0022: 3.1019691748828695, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 56.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 32, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab kafka_probe \u00bb (signaux protocolaires) \u00b7 confiance 47%\u0022, \u0022confidence\u0022: 0.47, \u0022classification_confidence\u0022: 0.47, \u0022precision_score\u0022: 56, \u0022precision_signals\u0022: [\u0022pat-0556\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0556\u0022], \u0022matched_patterns\u0022: [\u0022pat-0556\u0022, \u0022pat-0577\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022, \u0022pat-0623\u0022], \u0022matched_pattern_names\u0022: [\u0022Kafka ApiVersions key\u0022, \u0022RADIUS Access-Request\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022, \u0022WireGuard handshake\u0022], \u0022pattern_ids\u0022: [\u0022pat-0556\u0022, \u0022pat-0577\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022, \u0022pat-0623\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 32}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 47.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022f884620dcffbd325c528857bf10be8ac\u0022, \u0022path_pattern_hash\u0022: \u0022369bfdf011acc5969bcb68a7ffd2ca13\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 32}, \u0022payload_snippet\u0022: \u0022\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd\\u000b\ufffd\ufffd\\u0000\\u0000\\u0000MMS\\u0014\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0012\\u0000\\u0000\\u0000\\u0001\\u0000\\u0003\\u0000\ufffd\ufffd\ufffd\ufffd\\u000b\\u0000\\u0004\\u0000\\u001c\\u0000\\u0003\\u0000N\\u0000S\\u0000P\\u0000l\\u0000a\\u0000y\\u0000e\\u0000r\\u0000\/\\u00009\\u0000.\\u00000\\u0000.\\u00000\\u0000.\\u00002\\u00009\\u00008\\u00000\\u0000;\\u0000 \\u0000{\\u00000\\u00000\\u00000\\u00000\\u0000A\\u0000A\\u00000\\u00000\\u0000-\\u00000\\u0000A\\u00000\\u00000\\u0000-\\u00000\\u00000\\u0000a\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd\\u000b\ufffd\ufffd\\u0000\\u0000\\u0000MMS\\u0014\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0012\\u0000\\u0000\\u0000\\u0001\\u0000\\u0003\\u0000\ufffd\ufffd\ufffd\ufffd\\u000b\\u0000\\u0004\\u0000\\u001c\\u0000\\u0003\\u0000N\\u0000S\\u0000P\\u0000l\\u0000a\\u0000y\\u0000e\\u0000r\\u0000\/\\u00009\\u0000.\\u00000\\u0000.\\u00000\\u0000.\\u00002\\u00009\\u00008\\u00000\\u0000;\\u0000 \\u0000{\\u00000\\u00000\\u00000\\u00000\\u0000A\\u0000A\\u00000\\u00000\\u0000-\\u00000\\u0000A\\u00000\\u00000\\u0000-\\u00000\\u00000\\u0000a\\u00000\\u0000-\\u0000A\\u0000A\\u00000\\u0000A\\u0000-\\u00000\\u00000\\u00000\\u00000\\u0000A\\u00000\\u0000A\\u0000A\\u00000\\u0000A\\u0000A\\u00000\\u0000}\\u0000\\u0000\\u0000\ufffdm\ufffd_\u0022, \u0022payload_snippet\u0022: \u0022\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd\\u000b\ufffd\ufffd\\u0000\\u0000\\u0000MMS\\u0014\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0012\\u0000\\u0000\\u0000\\u0001\\u0000\\u0003\\u0000\ufffd\ufffd\ufffd\ufffd\\u000b\\u0000\\u0004\\u0000\\u001c\\u0000\\u0003\\u0000N\\u0000S\\u0000P\\u0000l\\u0000a\\u0000y\\u0000e\\u0000r\\u0000\/\\u00009\\u0000.\\u00000\\u0000.\\u00000\\u0000.\\u00002\\u00009\\u00008\\u00000\\u0000;\\u0000 \\u0000{\\u00000\\u00000\\u00000\\u00000\\u0000A\\u0000A\\u00000\\u00000\\u0000-\\u00000\\u0000A\\u00000\\u00000\\u0000-\\u00000\\u00000\\u0000a\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab kafka_probe \u00bb (signaux protocolaires) \u00b7 confiance 47%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022enterprise_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022fde3c9db65dd329c2e18cf31a49db93ecff637ec\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd\\u000b\ufffd\ufffd\\u0000\\u0000\\u0000MMS\\u0014\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0012\\u0000\\u0000\\u0000\\u0001\\u0000\\u0003\\u0000\ufffd\ufffd\ufffd\ufffd\\u000b\\u0000\\u0004\\u0000\\u001c\\u0000\\u0003\\u0000N\\u0000S\\u0000P\\u0000l\\u0000a\\u0000y\\u0000e\\u0000r\\u0000\/\\u00009\\u0000.\\u00000\\u0000.\\u00000\\u0000.\\u00002\\u00009\\u00008\\u00000\\u0000;\\u0000 \\u0000{\\u00000\\u00000\\u00000\\u00000\\u0000A\\u0000A\\u00000\\u00000\\u0000-\\u00000\\u0000A\\u00000\\u00000\\u0000-\\u00000\\u00000\\u0000a\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffd\ufffd\ufffd\ufffdMMS\ufffd\ufffd\ufffd\ufffdNSPlayer\/9.0.0.2980; {0000AA00-0A00-00a\u0022, \u0022attack_vector\u0022: \u0022kafka probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 47 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab kafka_probe \u00bb (signaux protocolaires) \u00b7 confiance 47%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab kafka_probe \u00bb (signaux protocolaires) \u00b7 confiance 47%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 32\/100\u0022, \u0022confidence_pct\u0022: 47, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 32}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 32, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0556\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0556\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd\\u000b\ufffd\ufffd\\u0000\\u0000\\u0000MMS\\u0014\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0012\\u0000\\u0000\\u0000\\u0001\\u0000\\u0003\\u0000\ufffd\ufffd\ufffd\ufffd\\u000b\\u0000\\u0004\\u0000\\u001c\\u0000\\u0003\\u0000N\\u0000S\\u0000P\\u0000l\\u0000a\\u0000y\\u0000e\\u0000r\\u0000\/\\u00009\\u0000.\\u00000\\u0000.\\u00000\\u0000.\\u00002\\u00009\\u00008\\u00000\\u0000;\\u0000 \\u0000{\\u00000\\u00000\\u00000\\u00000\\u0000A\\u0000A\\u00000\\u00000\\u0000-\\u00000\\u0000A\\u00000\\u00000\\u0000-\\u00000\\u00000\\u0000a\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022kafka probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffd\ufffd\ufffd\ufffdMMS\ufffd\ufffd\ufffd\ufffdNSPlayer\/9.0.0.2980; {0000AA00-0A00-00a\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 47 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 47 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":175},{"id":9631825,"ip":"165.154.40.205","ts":"2026-06-19 04:14:39.000000","proto":"tcp","src_port":40010,"dst_port":4567,"service":"aws-ecs-agent","classification":"java_rmi_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 7, \u0022payload_entropy\u0022: 2.807354922057604, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 56.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 32, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab java_rmi_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0604\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0604\u0022], \u0022matched_patterns\u0022: [\u0022pat-0604\u0022], \u0022matched_pattern_names\u0022: [\u0022Java RMI JRMI\u0022], \u0022pattern_ids\u0022: [\u0022pat-0604\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 32}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022d8c49a0f759e2102fb8fa8368049d06a\u0022, \u0022path_pattern_hash\u0022: \u00227a566ca86213ccd15a91c0b5a885a24f\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 32}, \u0022payload_preview\u0022: \u0022JRMI\\u0000\\u0002K\u0022, \u0022request_sample\u0022: \u0022JRMI\\u0000\\u0002K\u0022, \u0022payload_snippet\u0022: \u0022JRMI\\u0000\\u0002K\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022JRMI\\u0000\\u0002K\u0022, \u0022payload_snippet\u0022: \u0022JRMI\\u0000\\u0002K\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab java_rmi_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022enterprise_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002294f11c978a3022741f78dbb6bde8424cc19793b0\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022JRMI\\u0000\\u0002K\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022JRMIK\u0022, \u0022attack_vector\u0022: \u0022java rmi probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab java_rmi_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab java_rmi_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 32\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 32}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 32, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0604\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0604\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022JRMI\\u0000\\u0002K\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022java rmi probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022JRMIK\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":7},{"id":9631823,"ip":"165.154.40.205","ts":"2026-06-19 04:14:36.000000","proto":"tcp","src_port":39306,"dst_port":4567,"service":"aws-ecs-agent","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 60, \u0022payload_entropy\u0022: 1.3389205950315934, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 10.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.4, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 10.0}, \u0022risk_score\u0022: 33, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022cf83115deb0c0fa52ae4db8bd18e6e07550f2c26\u0022, \u0022event_fingerprint\u0022: \u0022b015205f7547696e8eef94fa78be166157bf55c5\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 80%\u0022, \u0022confidence\u0022: 0.8, \u0022classification_confidence\u0022: 0.8, \u0022precision_score\u0022: 90, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0532\u0022, \u0022pat-0768\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022NFS RPC mount\u0022, \u0022Mumble ping\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0532\u0022, \u0022pat-0768\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 10.0, \u0022risk_score\u0022: 33}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 80.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022f60433e5ca098d6d06ab4b829e9f35c4\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 33}, \u0022payload_preview\u0022: \u0022:\\u0000\\u0000\\u0000\/\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000@\\u0002\\u000f\\u0000\\u0001\\u0000=\\u0005\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\/\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000@\\u001f\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022request_sample\u0022: \u0022:\\u0000\\u0000\\u0000\/\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000@\\u0002\\u000f\\u0000\\u0001\\u0000=\\u0005\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\/\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000@\\u001f\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022:\\u0000\\u0000\\u0000\/\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000@\\u0002\\u000f\\u0000\\u0001\\u0000=\\u0005\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\/\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000@\\u001f\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0000\\u0000\\u0000\/\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000@\\u0002\\u000f\\u0000\\u0001\\u0000=\\u0005\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\/\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000@\\u001f\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022:\\u0000\\u0000\\u0000\/\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000@\\u0002\\u000f\\u0000\\u0001\\u0000=\\u0005\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\/\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000@\\u001f\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 80%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022fe755aa7e3f7179918f90fb190770546f0e22da5\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022:\\u0000\\u0000\\u0000\/\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000@\\u0002\\u000f\\u0000\\u0001\\u0000=\\u0005\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\/\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000@\\u001f\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022:\/@=\/@\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 80 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 80%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 80%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 33\/100\u0022, \u0022confidence_pct\u0022: 80, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 10.0, \u0022risk_score\u0022: 33}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 33, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022:\\u0000\\u0000\\u0000\/\\u0000\\u0000\\u0000\\u0002\\u0000\\u0000@\\u0002\\u000f\\u0000\\u0001\\u0000=\\u0005\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\/\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000@\\u001f\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\/@=\/@\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 80 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 80 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":60},{"id":9631821,"ip":"165.154.40.205","ts":"2026-06-19 04:14:33.000000","proto":"tcp","src_port":38384,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 23, \u0022payload_entropy\u0022: 2.6081816167087406, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0771\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022947f08e762562490af13d3254ff011a6\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022DmdT\\u0000\\u0000\\u0000\\u0017\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0011\\u0011\\u0000\ufffd\\u0001\ufffd\\u0013\u0022, \u0022request_sample\u0022: \u0022DmdT\\u0000\\u0000\\u0000\\u0017\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0011\\u0011\\u0000\ufffd\\u0001\ufffd\\u0013\u0022, \u0022payload_snippet\u0022: \u0022DmdT\\u0000\\u0000\\u0000\\u0017\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0011\\u0011\\u0000\ufffd\\u0001\ufffd\\u0013\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022DmdT\\u0000\\u0000\\u0000\\u0017\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0011\\u0011\\u0000\ufffd\\u0001\ufffd\\u0013\u0022, \u0022payload_snippet\u0022: \u0022DmdT\\u0000\\u0000\\u0000\\u0017\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0011\\u0011\\u0000\ufffd\\u0001\ufffd\\u0013\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022d18d2727ae4ecdc5c1e20e07eb1ca477f5b44753\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022DmdT\\u0000\\u0000\\u0000\\u0017\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0011\\u0011\\u0000\ufffd\\u0001\ufffd\\u0013\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022DmdT\ufffd\ufffd\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0771\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0771\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022DmdT\\u0000\\u0000\\u0000\\u0017\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0011\\u0011\\u0000\ufffd\\u0001\ufffd\\u0013\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022DmdT\ufffd\ufffd\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":23},{"id":9631817,"ip":"165.154.40.205","ts":"2026-06-19 04:14:30.000000","proto":"tcp","src_port":37510,"dst_port":4567,"service":"aws-ecs-agent","classification":"port_4567_tcp","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 22, \u0022payload_entropy\u0022: 3.133919825058653, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 38.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 38.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 41, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_4567_tcp \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0348\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0348\u0022], \u0022matched_patterns\u0022: [\u0022pat-0348\u0022, \u0022pat-0376\u0022, \u0022pat-0868\u0022, \u0022pat-0554\u0022], \u0022matched_pattern_names\u0022: [\u0022RDP TPKT header\u0022, \u0022S7 TPKT packet\u0022, \u0022ET H.323 setup\u0022, \u0022Minecraft varint handshake\u0022], \u0022pattern_ids\u0022: [\u0022pat-0348\u0022, \u0022pat-0376\u0022, \u0022pat-0868\u0022, \u0022pat-0554\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 38.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 41}, \u0022named_classification_skipped\u0022: true, \u0022named_candidate\u0022: \u0022rdp_probe\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022097791b86f9950e021480f7ef5b4d939\u0022, \u0022path_pattern_hash\u0022: \u0022f864580abc1c51fefa22b7b9a4b84104\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 41}, \u0022payload_preview\u0022: \u0022\\u0003\\u0000\\u0000\\u0016\\u0011\ufffd\\u0000\\u0000\\u0000\\u0014\\u0000\ufffd\\u0002\\u0001\\u0000\ufffd\\u0002\\u0001\\u0002\ufffd\\u0001\\n\u0022, \u0022request_sample\u0022: \u0022\\u0003\\u0000\\u0000\\u0016\\u0011\ufffd\\u0000\\u0000\\u0000\\u0014\\u0000\ufffd\\u0002\\u0001\\u0000\ufffd\\u0002\\u0001\\u0002\ufffd\\u0001\\n\u0022, \u0022payload_snippet\u0022: \u0022\\u0003\\u0000\\u0000\\u0016\\u0011\ufffd\\u0000\\u0000\\u0000\\u0014\\u0000\ufffd\\u0002\\u0001\\u0000\ufffd\\u0002\\u0001\\u0002\ufffd\\u0001\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0003\\u0000\\u0000\\u0016\\u0011\ufffd\\u0000\\u0000\\u0000\\u0014\\u0000\ufffd\\u0002\\u0001\\u0000\ufffd\\u0002\\u0001\\u0002\ufffd\\u0001\\n\u0022, \u0022payload_snippet\u0022: \u0022\\u0003\\u0000\\u0000\\u0016\\u0011\ufffd\\u0000\\u0000\\u0000\\u0014\\u0000\ufffd\\u0002\\u0001\\u0000\ufffd\\u0002\\u0001\\u0002\ufffd\\u0001\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_4567_tcp \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022ad27a910f5c1cae518da67785ffa818dc37c7b9e\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0003\\u0000\\u0000\\u0016\\u0011\ufffd\\u0000\\u0000\\u0000\\u0014\\u0000\ufffd\\u0002\\u0001\\u0000\ufffd\\u0002\\u0001\\u0002\ufffd\\u0001\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffd\ufffd\ufffd\u0022, \u0022attack_vector\u0022: \u0022port 4567 tcp \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9 \u00b7 Classification nomm\u00e9e non retenue \u2014 preuves insuffisantes\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab port_4567_tcp \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab port_4567_tcp \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 41\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 38.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 41}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 41, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0348\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0348\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0003\\u0000\\u0000\\u0016\\u0011\ufffd\\u0000\\u0000\\u0000\\u0014\\u0000\ufffd\\u0002\\u0001\\u0000\ufffd\\u0002\\u0001\\u0002\ufffd\\u0001\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022port 4567 tcp \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffd\ufffd\ufffd\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9 \u00b7 Classification nomm\u00e9e non retenue \u2014 preuves insuffisantes\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":22},{"id":9631816,"ip":"165.154.40.205","ts":"2026-06-19 04:14:27.000000","proto":"tcp","src_port":36750,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 11, \u0022payload_entropy\u0022: 2.4040097573248604, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0554\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002295bb1798cbe14e09d8a7b5feb33c741f\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\ufffdt\\u0000\\u0000\\u0000\\u0005\\u0000+\\u000e\\u0001\\u0000\u0022, \u0022request_sample\u0022: \u0022\ufffdt\\u0000\\u0000\\u0000\\u0005\\u0000+\\u000e\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\ufffdt\\u0000\\u0000\\u0000\\u0005\\u0000+\\u000e\\u0001\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\ufffdt\\u0000\\u0000\\u0000\\u0005\\u0000+\\u000e\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\ufffdt\\u0000\\u0000\\u0000\\u0005\\u0000+\\u000e\\u0001\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022b91e88a8cb9d7118356f8e0870c39205ac618f3c\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\ufffdt\\u0000\\u0000\\u0000\\u0005\\u0000+\\u000e\\u0001\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffdt+\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0554\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0554\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\ufffdt\\u0000\\u0000\\u0000\\u0005\\u0000+\\u000e\\u0001\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffdt+\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022], \u0022behavior_alert_count\u0022: 2, \u0022behavior_priority\u0022: 72}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":11},{"id":9631812,"ip":"165.154.40.205","ts":"2026-06-19 04:14:24.000000","proto":"tcp","src_port":35906,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 56, \u0022payload_entropy\u0022: 3.7279714939527033, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0554\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022fca620885715d4e346da0f82d84da595\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000\\u0006\\u0000\\u0000\\u00000.26.0\\u0007\\u0000\\u0000\\u00000.26.10202cb962ac59075b964b07152d234b70\u0022, \u0022request_sample\u0022: \u0022\\u0000\\u0000\\u0000\\u0006\\u0000\\u0000\\u00000.26.0\\u0007\\u0000\\u0000\\u00000.26.10202cb962ac59075b964b07152d234b70\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\\u0000\\u0000\\u0006\\u0000\\u0000\\u00000.26.0\\u0007\\u0000\\u0000\\u00000.26.10202cb962ac59075b964b07152d234b70\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0000\\u0000\\u0000\\u0006\\u0000\\u0000\\u00000.26.0\\u0007\\u0000\\u0000\\u00000.26.10202cb962ac59075b964b07152d234b70\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\\u0000\\u0000\\u0006\\u0000\\u0000\\u00000.26.0\\u0007\\u0000\\u0000\\u00000.26.10202cb962ac59075b964b07152d234b70\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00227766d9757527091340089b3f8ca5dbf73b208dbe\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000\\u0006\\u0000\\u0000\\u00000.26.0\\u0007\\u0000\\u0000\\u00000.26.10202cb962ac59075b964b07152d234b70\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u00220.26.00.26.10202cb962ac59075b964b07152d234b70\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0554\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0554\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000\\u0006\\u0000\\u0000\\u00000.26.0\\u0007\\u0000\\u0000\\u00000.26.10202cb962ac59075b964b07152d234b70\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u00220.26.00.26.10202cb962ac59075b964b07152d234b70\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":56},{"id":9631809,"ip":"165.154.40.205","ts":"2026-06-19 04:14:21.000000","proto":"tcp","src_port":35012,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 49, \u0022payload_entropy\u0022: 4.193778152167447, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 10.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.4, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 10.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022ec0cec87955d158d29ba612207f900df004913a5\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0554\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 10.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022493a3d213b080175a70a3be3bdf3d870\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022)\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000{\\\u0022Type\\\u0022:\\\u0022Auth\\\u0022,\\\u0022Payload\\\u0022:{\\\u0022Version\\\u0022:\\\u00222\\\u0022}}\u0022, \u0022request_sample\u0022: \u0022)\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000{\\\u0022Type\\\u0022:\\\u0022Auth\\\u0022,\\\u0022Payload\\\u0022:{\\\u0022Version\\\u0022:\\\u00222\\\u0022}}\u0022, \u0022payload_snippet\u0022: \u0022)\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000{\\\u0022Type\\\u0022:\\\u0022Auth\\\u0022,\\\u0022Payload\\\u0022:{\\\u0022Version\\\u0022:\\\u00222\\\u0022}}\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022)\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000{\\\u0022Type\\\u0022:\\\u0022Auth\\\u0022,\\\u0022Payload\\\u0022:{\\\u0022Version\\\u0022:\\\u00222\\\u0022}}\u0022, \u0022payload_snippet\u0022: \u0022)\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000{\\\u0022Type\\\u0022:\\\u0022Auth\\\u0022,\\\u0022Payload\\\u0022:{\\\u0022Version\\\u0022:\\\u00222\\\u0022}}\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022131a94f53bcd71e1cc5e1da8e7b412ca5a8a03ea\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022)\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000{\\\u0022Type\\\u0022:\\\u0022Auth\\\u0022,\\\u0022Payload\\\u0022:{\\\u0022Version\\\u0022:\\\u00222\\\u0022}}\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022){\\\u0022Type\\\u0022:\\\u0022Auth\\\u0022,\\\u0022Payload\\\u0022:{\\\u0022Version\\\u0022:\\\u00222\\\u0022}}\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 10.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0554\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0554\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022)\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000{\\\u0022Type\\\u0022:\\\u0022Auth\\\u0022,\\\u0022Payload\\\u0022:{\\\u0022Version\\\u0022:\\\u00222\\\u0022}}\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022){\\\u0022Type\\\u0022:\\\u0022Auth\\\u0022,\\\u0022Payload\\\u0022:{\\\u0022Version\\\u0022:\\\u00222\\\u0022}}\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022mongodb_version\u0022, \u0022mongodb_version_2\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022mongodb_version\u0022, \u0022mongodb_version_2\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":49},{"id":9631807,"ip":"165.154.40.205","ts":"2026-06-19 04:14:18.000000","proto":"tcp","src_port":34202,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 12, \u0022payload_entropy\u0022: 0.8112781244591328, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0771\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002289fcddd8e965f8ff958358b927013df6\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\\u0000\\u0001\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\u0022, \u0022request_sample\u0022: \u0022\\u0000\\u0001\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\\u0001\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0000\\u0001\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\\u0001\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022b24a89ce0695fe5be3820eaa310a6e7da2a6a4cc\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\\u0001\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0771\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0771\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\\u0001\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: null, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":12},{"id":9631801,"ip":"165.154.40.205","ts":"2026-06-19 04:14:15.000000","proto":"tcp","src_port":33584,"dst_port":4567,"service":"aws-ecs-agent","classification":"opcua_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 59, \u0022payload_entropy\u0022: 3.860214023388077, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab opcua_probe \u00bb (signaux protocolaires) \u00b7 confiance 47%\u0022, \u0022confidence\u0022: 0.47, \u0022classification_confidence\u0022: 0.47, \u0022precision_score\u0022: 56, \u0022precision_signals\u0022: [\u0022pat-0626\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0626\u0022], \u0022matched_patterns\u0022: [\u0022pat-0103\u0022, \u0022pat-0626\u0022, \u0022pat-0554\u0022], \u0022matched_pattern_names\u0022: [\u0022LFI Double-dot bypass\u0022, \u0022OPC UA HEL\u0022, \u0022Minecraft varint handshake\u0022], \u0022pattern_ids\u0022: [\u0022pat-0103\u0022, \u0022pat-0626\u0022, \u0022pat-0554\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 35}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 47.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022405e43878bd2caed9a786695e348bf9d\u0022, \u0022path_pattern_hash\u0022: \u00229665a326f7d8f70f1661dab78807b951\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 35}, \u0022payload_preview\u0022: \u0022HELF;\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u001b\\u0000\\u0000\\u0000opc.tcp:\/\/85.214.126.3:4840\u0022, \u0022request_sample\u0022: \u0022HELF;\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u001b\\u0000\\u0000\\u0000opc.tcp:\/\/85.214.126.3:4840\u0022, \u0022payload_snippet\u0022: \u0022HELF;\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u001b\\u0000\\u0000\\u0000opc.tcp:\/\/85.214.126.3:4840\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022HELF;\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u001b\\u0000\\u0000\\u0000opc.tcp:\/\/85.214.126.3:4840\u0022, \u0022payload_snippet\u0022: \u0022HELF;\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u001b\\u0000\\u0000\\u0000opc.tcp:\/\/85.214.126.3:4840\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab opcua_probe \u00bb (signaux protocolaires) \u00b7 confiance 47%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00227d1ba5a69a4c4ff9b45e2af4b5f6b92356c23aba\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022HELF;\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u001b\\u0000\\u0000\\u0000opc.tcp:\/\/85.214.126.3:4840\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022HELF;\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdopc.tcp:\/\/85.214.126.3:4840\u0022, \u0022attack_vector\u0022: \u0022opcua probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 47 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab opcua_probe \u00bb (signaux protocolaires) \u00b7 confiance 47%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab opcua_probe \u00bb (signaux protocolaires) \u00b7 confiance 47%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 35\/100\u0022, \u0022confidence_pct\u0022: 47, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 35}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 35, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0626\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0626\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022HELF;\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u001b\\u0000\\u0000\\u0000opc.tcp:\/\/85.214.126.3:4840\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022opcua probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022HELF;\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdopc.tcp:\/\/85.214.126.3:4840\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 47 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 47 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":59},{"id":9631799,"ip":"165.154.40.205","ts":"2026-06-19 04:14:12.000000","proto":"tcp","src_port":32826,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 16, \u0022payload_entropy\u0022: 1.6216407621868583, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0554\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022f49be22988ace8a28a7eea705f9e0c37\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\\u0010\\u0000\\u0000\\u0000G\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\\u0000\ufffd\\u0000\u0022, \u0022request_sample\u0022: \u0022\\u0010\\u0000\\u0000\\u0000G\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\\u0000\ufffd\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0010\\u0000\\u0000\\u0000G\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\\u0000\ufffd\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0010\\u0000\\u0000\\u0000G\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\\u0000\ufffd\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0010\\u0000\\u0000\\u0000G\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\\u0000\ufffd\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002212007a0c98f9091f89d42a1341b67e1431365aab\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0010\\u0000\\u0000\\u0000G\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\\u0000\ufffd\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022G\ufffd\ufffd\ufffd\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0554\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0554\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0010\\u0000\\u0000\\u0000G\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\\u0000\ufffd\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022G\ufffd\ufffd\ufffd\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":16},{"id":9631796,"ip":"165.154.40.205","ts":"2026-06-19 04:14:09.000000","proto":"tcp","src_port":60394,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 113, \u0022payload_entropy\u0022: 4.641748802606944, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0554\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002294179f64d7c7524a23b3cbf2af232c73\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000m\\u0000\\u0000\\u0000i{\\\u0022code\\\u0022:105,\\\u0022language\\\u0022:\\\u0022GO\\\u0022,\\\u0022version\\\u0022:317,\\\u0022opaque\\\u0022:2,\\\u0022flag\\\u0022:0,\\\u0022remark\\\u0022:\\\u0022\\\u0022,\\\u0022extFields\\\u0022:{\\\u0022topic\\\u0022:\\\u0022TBW102\\\u0022}}\u0022, \u0022request_sample\u0022: \u0022\\u0000\\u0000\\u0000m\\u0000\\u0000\\u0000i{\\\u0022code\\\u0022:105,\\\u0022language\\\u0022:\\\u0022GO\\\u0022,\\\u0022version\\\u0022:317,\\\u0022opaque\\\u0022:2,\\\u0022flag\\\u0022:0,\\\u0022remark\\\u0022:\\\u0022\\\u0022,\\\u0022extFields\\\u0022:{\\\u0022topic\\\u0022:\\\u0022TBW102\\\u0022}}\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\\u0000\\u0000m\\u0000\\u0000\\u0000i{\\\u0022code\\\u0022:105,\\\u0022language\\\u0022:\\\u0022GO\\\u0022,\\\u0022version\\\u0022:317,\\\u0022opaque\\\u0022:2,\\\u0022flag\\\u0022:0,\\\u0022remark\\\u0022:\\\u0022\\\u0022,\\\u0022extFields\\\u0022:{\\\u0022topic\\\u0022:\\\u0022TBW102\\\u0022}}\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0000\\u0000\\u0000m\\u0000\\u0000\\u0000i{\\\u0022code\\\u0022:105,\\\u0022language\\\u0022:\\\u0022GO\\\u0022,\\\u0022version\\\u0022:317,\\\u0022opaque\\\u0022:2,\\\u0022flag\\\u0022:0,\\\u0022remark\\\u0022:\\\u0022\\\u0022,\\\u0022extFields\\\u0022:{\\\u0022topic\\\u0022:\\\u0022TBW102\\\u0022}}\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\\u0000\\u0000m\\u0000\\u0000\\u0000i{\\\u0022code\\\u0022:105,\\\u0022language\\\u0022:\\\u0022GO\\\u0022,\\\u0022version\\\u0022:317,\\\u0022opaque\\\u0022:2,\\\u0022flag\\\u0022:0,\\\u0022remark\\\u0022:\\\u0022\\\u0022,\\\u0022extFields\\\u0022:{\\\u0022topic\\\u0022:\\\u0022TBW102\\\u0022}}\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002295afd443ca652dab762be44df8a35381ae823c6b\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000m\\u0000\\u0000\\u0000i{\\\u0022code\\\u0022:105,\\\u0022language\\\u0022:\\\u0022GO\\\u0022,\\\u0022version\\\u0022:317,\\\u0022opaque\\\u0022:2,\\\u0022flag\\\u0022:0,\\\u0022remark\\\u0022:\\\u0022\\\u0022,\\\u0022extFields\\\u0022:{\\\u0022topic\\\u0022:\\\u0022TBW102\\\u0022}}\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022mi{\\\u0022code\\\u0022:105,\\\u0022language\\\u0022:\\\u0022GO\\\u0022,\\\u0022version\\\u0022:317,\\\u0022opaque\\\u0022:2,\\\u0022flag\\\u0022:0,\\\u0022remark\\\u0022:\\\u0022\\\u0022,\\\u0022extFields\\\u0022:{\\\u0022topic\\\u0022:\\\u0022TBW102\\\u0022}}\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0554\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0554\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000m\\u0000\\u0000\\u0000i{\\\u0022code\\\u0022:105,\\\u0022language\\\u0022:\\\u0022GO\\\u0022,\\\u0022version\\\u0022:317,\\\u0022opaque\\\u0022:2,\\\u0022flag\\\u0022:0,\\\u0022remark\\\u0022:\\\u0022\\\u0022,\\\u0022extFields\\\u0022:{\\\u0022topic\\\u0022:\\\u0022TBW102\\\u0022}}\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022mi{\\\u0022code\\\u0022:105,\\\u0022language\\\u0022:\\\u0022GO\\\u0022,\\\u0022version\\\u0022:317,\\\u0022opaque\\\u0022:2,\\\u0022flag\\\u0022:0,\\\u0022remark\\\u0022:\\\u0022\\\u0022,\\\u0022extFields\\\u0022:{\\\u0022topic\\\u0022:\\\u0022TBW102\\\u0022}}\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":113},{"id":9631795,"ip":"165.154.40.205","ts":"2026-06-19 04:14:06.000000","proto":"tcp","src_port":59672,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 131, \u0022payload_entropy\u0022: 4.943692969509017, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0771\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00227ac31581d9769a3294f2b8ec05c3e9e6\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u00222W\\u0000\\u0000\\u0000\\u00012C\\u0000\\u0000\\u0000wx^\\u0000j\\u0000\ufffd\ufffd2J\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000`{\\\u0022@timestamp\\\u0022:\\\u00222023-11-10T16:31:19.3549634+08:00\\\u0022,\\\u0022message\\\u0022:\\\u0022t\\\u0022,\\\u0022offset\\\u0022:1000,\\\u0022type\\\u0022:\\\u0022filebeat\\\u0022}\\u0003\\u00006\u0022, \u0022request_sample\u0022: \u00222W\\u0000\\u0000\\u0000\\u00012C\\u0000\\u0000\\u0000wx^\\u0000j\\u0000\ufffd\ufffd2J\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000`{\\\u0022@timestamp\\\u0022:\\\u00222023-11-10T16:31:19.3549634+08:00\\\u0022,\\\u0022message\\\u0022:\\\u0022t\\\u0022,\\\u0022offset\\\u0022:1000,\\\u0022type\\\u0022:\\\u0022filebeat\\\u0022}\\u0003\\u00006\ufffd\\u001b\u0022, \u0022payload_snippet\u0022: \u00222W\\u0000\\u0000\\u0000\\u00012C\\u0000\\u0000\\u0000wx^\\u0000j\\u0000\ufffd\ufffd2J\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000`{\\\u0022@timestamp\\\u0022:\\\u00222023-11-10T16:31:19.3549634+08:00\\\u0022,\\\u0022message\\\u0022:\\\u0022t\\\u0022,\\\u0022offset\\\u0022:1000,\\\u0022type\\\u0022:\\\u0022filebeat\\\u0022}\\u0003\\u00006\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u00222W\\u0000\\u0000\\u0000\\u00012C\\u0000\\u0000\\u0000wx^\\u0000j\\u0000\ufffd\ufffd2J\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000`{\\\u0022@timestamp\\\u0022:\\\u00222023-11-10T16:31:19.3549634+08:00\\\u0022,\\\u0022message\\\u0022:\\\u0022t\\\u0022,\\\u0022offset\\\u0022:1000,\\\u0022type\\\u0022:\\\u0022filebeat\\\u0022}\\u0003\\u00006\ufffd\\u001b\u0022, \u0022payload_snippet\u0022: \u00222W\\u0000\\u0000\\u0000\\u00012C\\u0000\\u0000\\u0000wx^\\u0000j\\u0000\ufffd\ufffd2J\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000`{\\\u0022@timestamp\\\u0022:\\\u00222023-11-10T16:31:19.3549634+08:00\\\u0022,\\\u0022message\\\u0022:\\\u0022t\\\u0022,\\\u0022offset\\\u0022:1000,\\\u0022type\\\u0022:\\\u0022filebeat\\\u0022}\\u0003\\u00006\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022a30d4e79c7fa29d50e0312dc8fbb10bc7a493749\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u00222W\\u0000\\u0000\\u0000\\u00012C\\u0000\\u0000\\u0000wx^\\u0000j\\u0000\ufffd\ufffd2J\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000`{\\\u0022@timestamp\\\u0022:\\\u00222023-11-10T16:31:19.3549634+08:00\\\u0022,\\\u0022message\\\u0022:\\\u0022t\\\u0022,\\\u0022offset\\\u0022:1000,\\\u0022type\\\u0022:\\\u0022filebeat\\\u0022}\\u0003\\u00006\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u00222W2Cwx^j\ufffd\ufffd2J`{\\\u0022@timestamp\\\u0022:\\\u00222023-11-10T16:31:19.3549634+08:00\\\u0022,\\\u0022message\\\u0022:\\\u0022t\\\u0022,\\\u0022offset\\\u0022:1000,\\\u0022type\\\u0022:\\\u0022filebeat\\\u0022}6\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0771\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0771\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u00222W\\u0000\\u0000\\u0000\\u00012C\\u0000\\u0000\\u0000wx^\\u0000j\\u0000\ufffd\ufffd2J\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000`{\\\u0022@timestamp\\\u0022:\\\u00222023-11-10T16:31:19.3549634+08:00\\\u0022,\\\u0022message\\\u0022:\\\u0022t\\\u0022,\\\u0022offset\\\u0022:1000,\\\u0022type\\\u0022:\\\u0022filebeat\\\u0022}\\u0003\\u00006\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u00222W2Cwx^j\ufffd\ufffd2J`{\\\u0022@timestamp\\\u0022:\\\u00222023-11-10T16:31:19.3549634+08:00\\\u0022,\\\u0022message\\\u0022:\\\u0022t\\\u0022,\\\u0022offset\\\u0022:1000,\\\u0022type\\\u0022:\\\u0022filebeat\\\u0022}6\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":131},{"id":9631792,"ip":"165.154.40.205","ts":"2026-06-19 04:14:03.000000","proto":"tcp","src_port":58922,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 29, \u0022payload_entropy\u0022: 4.064203408622266, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0554\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022a28a90b32f6006a6cfa98505ba373419\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000\\u0019a\\n\\u00074.6.2.3\\u0010\\u0006\\\u0022\\t8798306680\\u0001\u0022, \u0022request_sample\u0022: \u0022\\u0000\\u0000\\u0000\\u0019a\\n\\u00074.6.2.3\\u0010\\u0006\\\u0022\\t8798306680\\u0001\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\\u0000\\u0000\\u0019a\\n\\u00074.6.2.3\\u0010\\u0006\\\u0022\\t8798306680\\u0001\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0000\\u0000\\u0000\\u0019a\\n\\u00074.6.2.3\\u0010\\u0006\\\u0022\\t8798306680\\u0001\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\\u0000\\u0000\\u0019a\\n\\u00074.6.2.3\\u0010\\u0006\\\u0022\\t8798306680\\u0001\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022ed77ddcb165eb380380ad38e875422216b6d4f5a\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000\\u0019a\\n\\u00074.6.2.3\\u0010\\u0006\\\u0022\\t8798306680\\u0001\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022a\\n4.6.2.3\\\u0022\\t8798306680\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0554\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0554\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000\\u0019a\\n\\u00074.6.2.3\\u0010\\u0006\\\u0022\\t8798306680\\u0001\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022a\\n4.6.2.3\\\u0022\\t8798306680\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":29},{"id":9631789,"ip":"165.154.40.205","ts":"2026-06-19 04:14:00.000000","proto":"tcp","src_port":58212,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 93, \u0022payload_entropy\u0022: 4.682586603096229, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0554\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00224d682adf59b1d9e41be709f5ccbc8084\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\ufffd\ufffd\ufffd\ufffd\\u0000\\u0000]\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000I\\u0000\\u0000\\u0000223.75.123.71\\tIP\\tUSER\\tLOGON\\tQWRtaW4=\\tQWRtaW4=\\t\\t65536\\tUTF-8\\t805306367\\t1\\n\\n\\n\u0022, \u0022request_sample\u0022: \u0022\ufffd\ufffd\ufffd\ufffd\\u0000\\u0000]\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000I\\u0000\\u0000\\u0000223.75.123.71\\tIP\\tUSER\\tLOGON\\tQWRtaW4=\\tQWRtaW4=\\t\\t65536\\tUTF-8\\t805306367\\t1\\n\\n\\n\u0022, \u0022payload_snippet\u0022: \u0022\ufffd\ufffd\ufffd\ufffd\\u0000\\u0000]\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000I\\u0000\\u0000\\u0000223.75.123.71\\tIP\\tUSER\\tLOGON\\tQWRtaW4=\\tQWRtaW4=\\t\\t65536\\tUTF-8\\t805306367\\t1\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\ufffd\ufffd\ufffd\ufffd\\u0000\\u0000]\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000I\\u0000\\u0000\\u0000223.75.123.71\\tIP\\tUSER\\tLOGON\\tQWRtaW4=\\tQWRtaW4=\\t\\t65536\\tUTF-8\\t805306367\\t1\\n\\n\\n\u0022, \u0022payload_snippet\u0022: \u0022\ufffd\ufffd\ufffd\ufffd\\u0000\\u0000]\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000I\\u0000\\u0000\\u0000223.75.123.71\\tIP\\tUSER\\tLOGON\\tQWRtaW4=\\tQWRtaW4=\\t\\t65536\\tUTF-8\\t805306367\\t1\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022d8d873870503a874dbb288d6881a435ba552b8d7\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\ufffd\ufffd\ufffd\ufffd\\u0000\\u0000]\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000I\\u0000\\u0000\\u0000223.75.123.71\\tIP\\tUSER\\tLOGON\\tQWRtaW4=\\tQWRtaW4=\\t\\t65536\\tUTF-8\\t805306367\\t1\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffd\ufffd\ufffd]I223.75.123.71\\tIP\\tUSER\\tLOGON\\tQWRtaW4=\\tQWRtaW4=\\t\\t65536\\tUTF-8\\t805306367\\t1\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0554\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0554\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\ufffd\ufffd\ufffd\ufffd\\u0000\\u0000]\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000I\\u0000\\u0000\\u0000223.75.123.71\\tIP\\tUSER\\tLOGON\\tQWRtaW4=\\tQWRtaW4=\\t\\t65536\\tUTF-8\\t805306367\\t1\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffd\ufffd\ufffd]I223.75.123.71\\tIP\\tUSER\\tLOGON\\tQWRtaW4=\\tQWRtaW4=\\t\\t65536\\tUTF-8\\t805306367\\t1\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":93},{"id":9631786,"ip":"165.154.40.205","ts":"2026-06-19 04:13:57.000000","proto":"tcp","src_port":57408,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 32, \u0022payload_entropy\u0022: 1.498778124459133, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0771\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002248d1c4bf25ef5b6ad32d76fb795398b9\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\ufffd\\u0005\\u0000`\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0005\\u0002\\u0000\\u0001\\u0000\\u0000\ufffd\ufffd\u0022, \u0022request_sample\u0022: \u0022\ufffd\\u0005\\u0000`\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0005\\u0002\\u0000\\u0001\\u0000\\u0000\ufffd\ufffd\u0022, \u0022payload_snippet\u0022: \u0022\ufffd\\u0005\\u0000`\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0005\\u0002\\u0000\\u0001\\u0000\\u0000\ufffd\ufffd\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\ufffd\\u0005\\u0000`\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0005\\u0002\\u0000\\u0001\\u0000\\u0000\ufffd\ufffd\u0022, \u0022payload_snippet\u0022: \u0022\ufffd\\u0005\\u0000`\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0005\\u0002\\u0000\\u0001\\u0000\\u0000\ufffd\ufffd\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022ff7917ecdcee25c462f57d0c1721563450e1c47e\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\ufffd\\u0005\\u0000`\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0005\\u0002\\u0000\\u0001\\u0000\\u0000\ufffd\ufffd\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd`\ufffd\ufffd\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0771\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0771\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\ufffd\\u0005\\u0000`\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0005\\u0002\\u0000\\u0001\\u0000\\u0000\ufffd\ufffd\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd`\ufffd\ufffd\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":32},{"id":9631784,"ip":"165.154.40.205","ts":"2026-06-19 04:13:54.000000","proto":"tcp","src_port":56512,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 13, \u0022payload_entropy\u0022: 3.3927474104487847, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 34, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 34}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022b95100bea23f1bbc831cc0175ad22cfe\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 34}, \u0022payload_preview\u0022: \u0022EXAMPLE.COM\\r\\n\u0022, \u0022request_sample\u0022: \u0022EXAMPLE.COM\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022EXAMPLE.COM\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022EXAMPLE.COM\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022EXAMPLE.COM\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022bca225213c81bfea3317ec045431d623d9be3c57\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022EXAMPLE.COM\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022EXAMPLE.COM\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 3 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 34\/100\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 34}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 34, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022EXAMPLE.COM\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022EXAMPLE.COM\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 3 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022], \u0022behavior_alert_count\u0022: 2, \u0022behavior_priority\u0022: 72}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":13},{"id":9631782,"ip":"165.154.40.205","ts":"2026-06-19 04:13:51.000000","proto":"tcp","src_port":55834,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 179, \u0022payload_entropy\u0022: 5.098770336543975, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.4, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 34, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00229bba89324063edf444f76c17793b8fc9e5d64b70\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 34}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022c500383ebccf2fc673ea77e9e47d6daf\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 34}, \u0022payload_preview\u0022: \u0022{\\\u0022id\\\u0022:1,\\\u0022jsonrpc\\\u0022:\\\u00222.0\\\u0022,\\\u0022method\\\u0022:\\\u0022login\\\u0022,\\\u0022params\\\u0022:{\\\u0022login\\\u0022:\\\u0022YOUR_WALLET_ADDRESS\\\u0022,\\\u0022pass\\\u0022:\\\u0022x\\\u0022,\\\u0022agent\\\u0022:\\\u0022XMRig\/6.20.0-C3Pool\\\u0022,\\\u0022algo\\\u0022\u0022, \u0022request_sample\u0022: \u0022{\\\u0022id\\\u0022:1,\\\u0022jsonrpc\\\u0022:\\\u00222.0\\\u0022,\\\u0022method\\\u0022:\\\u0022login\\\u0022,\\\u0022params\\\u0022:{\\\u0022login\\\u0022:\\\u0022YOUR_WALLET_ADDRESS\\\u0022,\\\u0022pass\\\u0022:\\\u0022x\\\u0022,\\\u0022agent\\\u0022:\\\u0022XMRig\/6.20.0-C3Pool\\\u0022,\\\u0022algo\\\u0022:[\\\u0022cn\/1\\\u0022],\\\u0022algo-perf\\\u0022:{\\\u0022cn\/1\\\u0022:63.32038223248976}}}\\n\u0022, \u0022payload_snippet\u0022: \u0022{\\\u0022id\\\u0022:1,\\\u0022jsonrpc\\\u0022:\\\u00222.0\\\u0022,\\\u0022method\\\u0022:\\\u0022login\\\u0022,\\\u0022params\\\u0022:{\\\u0022login\\\u0022:\\\u0022YOUR_WALLET_ADDRESS\\\u0022,\\\u0022pass\\\u0022:\\\u0022x\\\u0022,\\\u0022agent\\\u0022:\\\u0022XMRig\/6.20.0-C3Pool\\\u0022,\\\u0022algo\\\u0022\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022{\\\u0022id\\\u0022:1,\\\u0022jsonrpc\\\u0022:\\\u00222.0\\\u0022,\\\u0022method\\\u0022:\\\u0022login\\\u0022,\\\u0022params\\\u0022:{\\\u0022login\\\u0022:\\\u0022YOUR_WALLET_ADDRESS\\\u0022,\\\u0022pass\\\u0022:\\\u0022x\\\u0022,\\\u0022agent\\\u0022:\\\u0022XMRig\/6.20.0-C3Pool\\\u0022,\\\u0022algo\\\u0022:[\\\u0022cn\/1\\\u0022],\\\u0022algo-perf\\\u0022:{\\\u0022cn\/1\\\u0022:63.32038223248976}}}\\n\u0022, \u0022payload_snippet\u0022: \u0022{\\\u0022id\\\u0022:1,\\\u0022jsonrpc\\\u0022:\\\u00222.0\\\u0022,\\\u0022method\\\u0022:\\\u0022login\\\u0022,\\\u0022params\\\u0022:{\\\u0022login\\\u0022:\\\u0022YOUR_WALLET_ADDRESS\\\u0022,\\\u0022pass\\\u0022:\\\u0022x\\\u0022,\\\u0022agent\\\u0022:\\\u0022XMRig\/6.20.0-C3Pool\\\u0022,\\\u0022algo\\\u0022\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022b6bbe6e8a4fe3890b7d38ee1bb2cdec646da7530\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022{\\\u0022id\\\u0022:1,\\\u0022jsonrpc\\\u0022:\\\u00222.0\\\u0022,\\\u0022method\\\u0022:\\\u0022login\\\u0022,\\\u0022params\\\u0022:{\\\u0022login\\\u0022:\\\u0022YOUR_WALLET_ADDRESS\\\u0022,\\\u0022pass\\\u0022:\\\u0022x\\\u0022,\\\u0022agent\\\u0022:\\\u0022XMRig\/6.20.0-C3Pool\\\u0022,\\\u0022algo\\\u0022\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022{\\\u0022id\\\u0022:1,\\\u0022jsonrpc\\\u0022:\\\u00222.0\\\u0022,\\\u0022method\\\u0022:\\\u0022login\\\u0022,\\\u0022params\\\u0022:{\\\u0022login\\\u0022:\\\u0022YOUR_WALLET_ADDRESS\\\u0022,\\\u0022pass\\\u0022:\\\u0022x\\\u0022,\\\u0022agent\\\u0022:\\\u0022XMRig\/6.20.0-C3Pool\\\u0022,\\\u0022algo\\\u0022\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 34\/100\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 34}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 34, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022{\\\u0022id\\\u0022:1,\\\u0022jsonrpc\\\u0022:\\\u00222.0\\\u0022,\\\u0022method\\\u0022:\\\u0022login\\\u0022,\\\u0022params\\\u0022:{\\\u0022login\\\u0022:\\\u0022YOUR_WALLET_ADDRESS\\\u0022,\\\u0022pass\\\u0022:\\\u0022x\\\u0022,\\\u0022agent\\\u0022:\\\u0022XMRig\/6.20.0-C3Pool\\\u0022,\\\u0022algo\\\u0022\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022{\\\u0022id\\\u0022:1,\\\u0022jsonrpc\\\u0022:\\\u00222.0\\\u0022,\\\u0022method\\\u0022:\\\u0022login\\\u0022,\\\u0022params\\\u0022:{\\\u0022login\\\u0022:\\\u0022YOUR_WALLET_ADDRESS\\\u0022,\\\u0022pass\\\u0022:\\\u0022x\\\u0022,\\\u0022agent\\\u0022:\\\u0022XMRig\/6.20.0-C3Pool\\\u0022,\\\u0022algo\\\u0022\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022cryptominer_probe\u0022, \u0022net_cloud_scanner\u0022, \u0022xmrig_pattern\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022cryptominer_probe\u0022, \u0022net_cloud_scanner\u0022, \u0022xmrig_pattern\u0022]","anomalies":"[]","severity":7,"bytes_in":179},{"id":9631781,"ip":"165.154.40.205","ts":"2026-06-19 04:13:48.000000","proto":"tcp","src_port":55134,"dst_port":4567,"service":"aws-ecs-agent","classification":"postgres_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 14, \u0022payload_entropy\u0022: 1.9502120649147467, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 40, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 116, \u0022precision_signals\u0022: [\u0022pat-0368\u0022, \u0022pat-0369\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0368\u0022, \u0022pat-0369\u0022], \u0022matched_patterns\u0022: [\u0022pat-0368\u0022, \u0022pat-0369\u0022, \u0022pat-0556\u0022, \u0022pat-0554\u0022], \u0022matched_pattern_names\u0022: [\u0022PostgreSQL cancel request\u0022, \u0022PostgreSQL startup\u0022, \u0022Kafka ApiVersions key\u0022, \u0022Minecraft varint handshake\u0022], \u0022pattern_ids\u0022: [\u0022pat-0368\u0022, \u0022pat-0369\u0022, \u0022pat-0556\u0022, \u0022pat-0554\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 40}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002219214bd9a0c01f9428154f3b658852b6\u0022, \u0022path_pattern_hash\u0022: \u002280f3c71fe26f36a0a9399108643f66c5\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 40}, \u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000\\n\\u0000\\u0012\\u0000\\u0000\ufffd\ufffd\ufffd\\u0000\\u0000\u0022, \u0022request_sample\u0022: \u0022\\u0000\\u0000\\u0000\\n\\u0000\\u0012\\u0000\\u0000\ufffd\ufffd\ufffd\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\\u0000\\u0000\\n\\u0000\\u0012\\u0000\\u0000\ufffd\ufffd\ufffd\\u0000\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0000\\u0000\\u0000\\n\\u0000\\u0012\\u0000\\u0000\ufffd\ufffd\ufffd\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\\u0000\\u0000\\n\\u0000\\u0012\\u0000\\u0000\ufffd\ufffd\ufffd\\u0000\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002227846e81b0f404cf1e506dfde58374627a6a2e10\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000\\n\\u0000\\u0012\\u0000\\u0000\ufffd\ufffd\ufffd\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffd\ufffd\u0022, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 40\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 40}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 40, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0368\u0022, \u0022pat-0369\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0368\u0022, \u0022pat-0369\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000\\n\\u0000\\u0012\\u0000\\u0000\ufffd\ufffd\ufffd\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffd\ufffd\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":14},{"id":9631775,"ip":"165.154.40.205","ts":"2026-06-19 04:13:45.000000","proto":"tcp","src_port":54434,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 40, \u0022payload_entropy\u0022: 3.2516094970590266, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0771\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022ade4c3e7a4c503a0785a09ddcef1efb8\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\ufffd\\u0001\\u0000\\u0001\\u0000\\u0000\\u0000\\u0014anonymous_command_on\\u0000\\u0000\\u0000\\u0000\\b\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022request_sample\u0022: \u0022\ufffd\\u0001\\u0000\\u0001\\u0000\\u0000\\u0000\\u0014anonymous_command_on\\u0000\\u0000\\u0000\\u0000\\b\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\ufffd\\u0001\\u0000\\u0001\\u0000\\u0000\\u0000\\u0014anonymous_command_on\\u0000\\u0000\\u0000\\u0000\\b\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\ufffd\\u0001\\u0000\\u0001\\u0000\\u0000\\u0000\\u0014anonymous_command_on\\u0000\\u0000\\u0000\\u0000\\b\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\ufffd\\u0001\\u0000\\u0001\\u0000\\u0000\\u0000\\u0014anonymous_command_on\\u0000\\u0000\\u0000\\u0000\\b\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002288103316e4eff7ddc7de2af6030cf90dd037ac02\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\ufffd\\u0001\\u0000\\u0001\\u0000\\u0000\\u0000\\u0014anonymous_command_on\\u0000\\u0000\\u0000\\u0000\\b\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffdanonymous_command_on\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0771\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0771\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\ufffd\\u0001\\u0000\\u0001\\u0000\\u0000\\u0000\\u0014anonymous_command_on\\u0000\\u0000\\u0000\\u0000\\b\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffdanonymous_command_on\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":40},{"id":9631771,"ip":"165.154.40.205","ts":"2026-06-19 04:13:42.000000","proto":"tcp","src_port":53684,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 39, \u0022payload_entropy\u0022: 4.6632313853624945, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0554\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022268e50c3963f0c6fe6ca87afd0ce66b8\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022#\\u0000\\u0000\\u0000\\u0012!\\u0010\\u0003\\u001a\\u0006:62710*\\rfd135ge@\u0026yt_02\\u0006123456\u0022, \u0022request_sample\u0022: \u0022#\\u0000\\u0000\\u0000\\u0012!\\u0010\\u0003\\u001a\\u0006:62710*\\rfd135ge@\u0026yt_02\\u0006123456\u0022, \u0022payload_snippet\u0022: \u0022#\\u0000\\u0000\\u0000\\u0012!\\u0010\\u0003\\u001a\\u0006:62710*\\rfd135ge@\u0026yt_02\\u0006123456\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022#\\u0000\\u0000\\u0000\\u0012!\\u0010\\u0003\\u001a\\u0006:62710*\\rfd135ge@\u0026yt_02\\u0006123456\u0022, \u0022payload_snippet\u0022: \u0022#\\u0000\\u0000\\u0000\\u0012!\\u0010\\u0003\\u001a\\u0006:62710*\\rfd135ge@\u0026yt_02\\u0006123456\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00226077a0100d88fa506d8a381fce477f05519245f6\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022#\\u0000\\u0000\\u0000\\u0012!\\u0010\\u0003\\u001a\\u0006:62710*\\rfd135ge@\u0026yt_02\\u0006123456\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022#!:62710*\\rfd135ge@\u0026yt_02123456\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0554\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0554\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022#\\u0000\\u0000\\u0000\\u0012!\\u0010\\u0003\\u001a\\u0006:62710*\\rfd135ge@\u0026yt_02\\u0006123456\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022#!:62710*\\rfd135ge@\u0026yt_02123456\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":39},{"id":9631770,"ip":"165.154.40.205","ts":"2026-06-19 04:13:39.000000","proto":"tcp","src_port":52976,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 43, \u0022payload_entropy\u0022: 5.10068335935326, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0554\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022f4f17bcdc73af477913b79f96989f7d8\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\ufffdx\\u0017\\u0001#\\u0000\\u0000\\u0000.\ufffd=\\b\ufffd\ufffd\ufffd$\\u0000\ufffd\u0027\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\u0017\ufffd\ufffdW\\u001dE\\u0005$e\ufffdV\ufffd\u003E\\\\\ufffd\u0022, \u0022request_sample\u0022: \u0022\ufffdx\\u0017\\u0001#\\u0000\\u0000\\u0000.\ufffd=\\b\ufffd\ufffd\ufffd$\\u0000\ufffd\u0027\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\u0017\ufffd\ufffdW\\u001dE\\u0005$e\ufffdV\ufffd\u003E\\\\\ufffd\u0022, \u0022payload_snippet\u0022: \u0022\ufffdx\\u0017\\u0001#\\u0000\\u0000\\u0000.\ufffd=\\b\ufffd\ufffd\ufffd$\\u0000\ufffd\u0027\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\u0017\ufffd\ufffdW\\u001dE\\u0005$e\ufffdV\ufffd\u003E\\\\\ufffd\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\ufffdx\\u0017\\u0001#\\u0000\\u0000\\u0000.\ufffd=\\b\ufffd\ufffd\ufffd$\\u0000\ufffd\u0027\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\u0017\ufffd\ufffdW\\u001dE\\u0005$e\ufffdV\ufffd\u003E\\\\\ufffd\u0022, \u0022payload_snippet\u0022: \u0022\ufffdx\\u0017\\u0001#\\u0000\\u0000\\u0000.\ufffd=\\b\ufffd\ufffd\ufffd$\\u0000\ufffd\u0027\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\u0017\ufffd\ufffdW\\u001dE\\u0005$e\ufffdV\ufffd\u003E\\\\\ufffd\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00229e4fb0c0f0d07c315a1a9e07a03ff2bf5b95c101\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\ufffdx\\u0017\\u0001#\\u0000\\u0000\\u0000.\ufffd=\\b\ufffd\ufffd\ufffd$\\u0000\ufffd\u0027\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\u0017\ufffd\ufffdW\\u001dE\\u0005$e\ufffdV\ufffd\u003E\\\\\ufffd\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffdx#.\ufffd=\ufffd\ufffd\ufffd$\ufffd\u0027\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdWE$e\ufffdV\ufffd\u003E\\\\\ufffd\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0554\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0554\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\ufffdx\\u0017\\u0001#\\u0000\\u0000\\u0000.\ufffd=\\b\ufffd\ufffd\ufffd$\\u0000\ufffd\u0027\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\u0017\ufffd\ufffdW\\u001dE\\u0005$e\ufffdV\ufffd\u003E\\\\\ufffd\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffdx#.\ufffd=\ufffd\ufffd\ufffd$\ufffd\u0027\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdWE$e\ufffdV\ufffd\u003E\\\\\ufffd\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":43},{"id":9631769,"ip":"165.154.40.205","ts":"2026-06-19 04:13:36.000000","proto":"tcp","src_port":52204,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 156, \u0022payload_entropy\u0022: 1.0056921668856296, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0771\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00225ca0ed1490012fe941f931322c79c1f4\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_snippet\u0022: \u0022\\u0000\ufffd\\u0000\\u0001\\u001a+\u003CM\\u0000\\u0001\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\ufffd\ufffd\\u0000\\u0001none\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000ppap\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0000\ufffd\\u0000\\u0001\\u001a+\u003CM\\u0000\\u0001\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\ufffd\ufffd\\u0000\\u0001none\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000ppap\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\ufffd\\u0000\\u0001\\u001a+\u003CM\\u0000\\u0001\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\ufffd\ufffd\\u0000\\u0001none\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000ppap\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022c48bf30aa275232771a2bf6289801415d5ef3fc0\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\ufffd\\u0000\\u0001\\u001a+\u003CM\\u0000\\u0001\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\ufffd\ufffd\\u0000\\u0001none\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000ppap\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd+\u003CM\ufffd\ufffdnoneppap\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0771\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0771\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\ufffd\\u0000\\u0001\\u001a+\u003CM\\u0000\\u0001\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0001\\u0000\\u0000\\u0000\\u0001\ufffd\ufffd\\u0000\\u0001none\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000ppap\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd+\u003CM\ufffd\ufffdnoneppap\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":156},{"id":9631768,"ip":"165.154.40.205","ts":"2026-06-19 04:13:33.000000","proto":"tcp","src_port":51422,"dst_port":4567,"service":"aws-ecs-agent","classification":"xss_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 144, \u0022payload_entropy\u0022: 4.6684321087757565, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 68.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 68.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 39, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab xss_attack \u00bb (signaux protocolaires) \u00b7 confiance 59%\u0022, \u0022confidence\u0022: 0.59, \u0022classification_confidence\u0022: 0.59, \u0022precision_score\u0022: 70, \u0022precision_signals\u0022: [\u0022pat-0284\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0284\u0022], \u0022matched_patterns\u0022: [\u0022pat-0284\u0022, \u0022pat-0103\u0022, \u0022pat-0530\u0022], \u0022matched_pattern_names\u0022: [\u0022CRS 941130\u0022, \u0022LFI Double-dot bypass\u0022, \u0022XMPP stream\u0022], \u0022pattern_ids\u0022: [\u0022pat-0284\u0022, \u0022pat-0103\u0022, \u0022pat-0530\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 68.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 39}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 59.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00222c2f7964ac7971e254cec36837483540\u0022, \u0022path_pattern_hash\u0022: \u0022e84c630ed8a3a6084c1b662f626e7300\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 39}, \u0022payload_preview\u0022: \u0022\u003C?xml version=\u00271.0\u0027?\u003E\u003Cstream:stream xmlns:stream=\u0027http:\/\/etherx.jabber.org\/streams\u0027 xmlns=\u0027jabber:client\u0027 xml:lang=\u0027ru-RU\u0027 to=\u0027.\u0022, \u0022request_sample\u0022: \u0022\u003C?xml version=\u00271.0\u0027?\u003E\u003Cstream:stream xmlns:stream=\u0027http:\/\/etherx.jabber.org\/streams\u0027 xmlns=\u0027jabber:client\u0027 xml:lang=\u0027ru-RU\u0027 to=\u0027.\u0027 version=\u00271.0\u0027\u003E\u0022, \u0022payload_snippet\u0022: \u0022\u003C?xml version=\u00271.0\u0027?\u003E\u003Cstream:stream xmlns:stream=\u0027http:\/\/etherx.jabber.org\/streams\u0027 xmlns=\u0027jabber:client\u0027 xml:lang=\u0027ru-RU\u0027 to=\u0027.\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\u003C?xml version=\u00271.0\u0027?\u003E\u003Cstream:stream xmlns:stream=\u0027http:\/\/etherx.jabber.org\/streams\u0027 xmlns=\u0027jabber:client\u0027 xml:lang=\u0027ru-RU\u0027 to=\u0027.\u0027 version=\u00271.0\u0027\u003E\u0022, \u0022payload_snippet\u0022: \u0022\u003C?xml version=\u00271.0\u0027?\u003E\u003Cstream:stream xmlns:stream=\u0027http:\/\/etherx.jabber.org\/streams\u0027 xmlns=\u0027jabber:client\u0027 xml:lang=\u0027ru-RU\u0027 to=\u0027.\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab xss_attack \u00bb (signaux protocolaires) \u00b7 confiance 59%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022e06df9b5c388b23c7b5b72e0d63f12fc177b51c2\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\u003C?xml version=\u00271.0\u0027?\u003E\u003Cstream:stream xmlns:stream=\u0027http:\/\/etherx.jabber.org\/streams\u0027 xmlns=\u0027jabber:client\u0027 xml:lang=\u0027ru-RU\u0027 to=\u0027.\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\u003C?xml version=\u00271.0\u0027?\u003E\u003Cstream:stream xmlns:stream=\u0027http:\/\/etherx.jabber.org\/streams\u0027 xmlns=\u0027jabber:client\u0027 xml:lang=\u0027ru-RU\u0027 to=\u0027.\u0022, \u0022attack_vector\u0022: \u0022xss attack \u00b7 via AWS ECS AGENT:4567 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 59 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab xss_attack \u00bb (signaux protocolaires) \u00b7 confiance 59%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab xss_attack \u00bb (signaux protocolaires) \u00b7 confiance 59%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 39\/100 (Faible) \u2014 MITRE TA0001 \u2014 confiance 59 % \u2014 via AWS ECS AGENT\u0022, \u0022confidence_pct\u0022: 59, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 68.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 39}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 39, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0284\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0284\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\u003C?xml version=\u00271.0\u0027?\u003E\u003Cstream:stream xmlns:stream=\u0027http:\/\/etherx.jabber.org\/streams\u0027 xmlns=\u0027jabber:client\u0027 xml:lang=\u0027ru-RU\u0027 to=\u0027.\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022xss attack \u00b7 via AWS ECS AGENT:4567 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022\u003C?xml version=\u00271.0\u0027?\u003E\u003Cstream:stream xmlns:stream=\u0027http:\/\/etherx.jabber.org\/streams\u0027 xmlns=\u0027jabber:client\u0027 xml:lang=\u0027ru-RU\u0027 to=\u0027.\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 59 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 59 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022], \u0022behavior_alert_count\u0022: 1, \u0022behavior_priority\u0022: 96}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":144},{"id":9631766,"ip":"165.154.40.205","ts":"2026-06-19 04:13:30.000000","proto":"tcp","src_port":50642,"dst_port":4567,"service":"aws-ecs-agent","classification":"mssql_tds","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 20, \u0022payload_entropy\u0022: 2.1709505944546685, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 56.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 32, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002276e3eec12032c48bbcad7893ab71523e54e5605a\u0022, \u0022event_fingerprint\u0022: \u0022b0d3fdd8f53738446ea599c55dda69e3d88716a2\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0768\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 32}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002278303524a43907117dd5e6de4f427da3\u0022, \u0022path_pattern_hash\u0022: \u0022285321e27377a1f85e5a231ca6cbffb2\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 32}, \u0022payload_preview\u0022: \u0022\\u0012\\u0002index\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0000\u0022, \u0022request_sample\u0022: \u0022\\u0012\\u0002index\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0012\\u0002index\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0012\\u0002index\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0012\\u0002index\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022fc3639817fcc0e97c24a37b6e024fb30110472a2\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0012\\u0002index\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022index\ufffd\u0022, \u0022attack_vector\u0022: \u0022mssql tds \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 32\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 32}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 32, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0768\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0768\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0012\\u0002index\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022mssql tds \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022index\ufffd\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022mssql_tds\u0022, \u0022net_mssql_tds\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022mssql_tds\u0022, \u0022net_mssql_tds\u0022]","anomalies":"[]","severity":5,"bytes_in":20},{"id":9631764,"ip":"165.154.40.205","ts":"2026-06-19 04:13:27.000000","proto":"tcp","src_port":49936,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 118, \u0022payload_entropy\u0022: 5.151202745659785, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0554\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022e4c389aa171b6c4fc8c08b745ec87f45\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\\u0006\ufffd\ufffdJoin\u00e5Nodes\\u0001\ufffdUserStateLen\\u0000\ufffd\ufffdAddr\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd8\\u0001\ufffdIncarnation\\u0001\ufffdMeta\ufffd\ufffdName\ufffdDESKTOP-NR8TTVR\ufffdPort\ufffd\\u001f\\n\ufffdState\\u0000\ufffdVsn\ufffd\\u0001\\u0005\\u0002\\u0000\\u0000\\u0000\u0022, \u0022request_sample\u0022: \u0022\\u0006\ufffd\ufffdJoin\u00e5Nodes\\u0001\ufffdUserStateLen\\u0000\ufffd\ufffdAddr\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd8\\u0001\ufffdIncarnation\\u0001\ufffdMeta\ufffd\ufffdName\ufffdDESKTOP-NR8TTVR\ufffdPort\ufffd\\u001f\\n\ufffdState\\u0000\ufffdVsn\ufffd\\u0001\\u0005\\u0002\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0006\ufffd\ufffdJoin\u00e5Nodes\\u0001\ufffdUserStateLen\\u0000\ufffd\ufffdAddr\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd8\\u0001\ufffdIncarnation\\u0001\ufffdMeta\ufffd\ufffdName\ufffdDESKTOP-NR8TTVR\ufffdPort\ufffd\\u001f\\n\ufffdState\\u0000\ufffdVsn\ufffd\\u0001\\u0005\\u0002\\u0000\\u0000\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0006\ufffd\ufffdJoin\u00e5Nodes\\u0001\ufffdUserStateLen\\u0000\ufffd\ufffdAddr\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd8\\u0001\ufffdIncarnation\\u0001\ufffdMeta\ufffd\ufffdName\ufffdDESKTOP-NR8TTVR\ufffdPort\ufffd\\u001f\\n\ufffdState\\u0000\ufffdVsn\ufffd\\u0001\\u0005\\u0002\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0006\ufffd\ufffdJoin\u00e5Nodes\\u0001\ufffdUserStateLen\\u0000\ufffd\ufffdAddr\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd8\\u0001\ufffdIncarnation\\u0001\ufffdMeta\ufffd\ufffdName\ufffdDESKTOP-NR8TTVR\ufffdPort\ufffd\\u001f\\n\ufffdState\\u0000\ufffdVsn\ufffd\\u0001\\u0005\\u0002\\u0000\\u0000\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00228d6165a00a4cdce930f9a01f1dfdba10d535712e\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0006\ufffd\ufffdJoin\u00e5Nodes\\u0001\ufffdUserStateLen\\u0000\ufffd\ufffdAddr\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd8\\u0001\ufffdIncarnation\\u0001\ufffdMeta\ufffd\ufffdName\ufffdDESKTOP-NR8TTVR\ufffdPort\ufffd\\u001f\\n\ufffdState\\u0000\ufffdVsn\ufffd\\u0001\\u0005\\u0002\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffdJoin\u00e5Nodes\ufffdUserStateLen\ufffd\ufffdAddr\ufffd\ufffd\ufffd\ufffd\ufffd8\ufffdIncarnation\ufffdMeta\ufffd\ufffdName\ufffdDESKTOP-NR8TTVR\ufffdPort\ufffd\\n\ufffdState\ufffdVsn\ufffd\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0554\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0554\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0006\ufffd\ufffdJoin\u00e5Nodes\\u0001\ufffdUserStateLen\\u0000\ufffd\ufffdAddr\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd8\\u0001\ufffdIncarnation\\u0001\ufffdMeta\ufffd\ufffdName\ufffdDESKTOP-NR8TTVR\ufffdPort\ufffd\\u001f\\n\ufffdState\\u0000\ufffdVsn\ufffd\\u0001\\u0005\\u0002\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffdJoin\u00e5Nodes\ufffdUserStateLen\ufffd\ufffdAddr\ufffd\ufffd\ufffd\ufffd\ufffd8\ufffdIncarnation\ufffdMeta\ufffd\ufffdName\ufffdDESKTOP-NR8TTVR\ufffdPort\ufffd\\n\ufffdState\ufffdVsn\ufffd\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":118},{"id":9631762,"ip":"165.154.40.205","ts":"2026-06-19 04:13:24.000000","proto":"tcp","src_port":49070,"dst_port":4567,"service":"aws-ecs-agent","classification":"rdp_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 11, \u0022payload_entropy\u0022: 1.6729330318733675, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 52.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 52.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 50, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab rdp_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 116, \u0022precision_signals\u0022: [\u0022pat-0348\u0022, \u0022pat-0352\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0348\u0022, \u0022pat-0352\u0022], \u0022matched_patterns\u0022: [\u0022pat-0348\u0022, \u0022pat-0352\u0022, \u0022pat-0868\u0022, \u0022pat-0768\u0022, \u0022pat-0554\u0022], \u0022matched_pattern_names\u0022: [\u0022RDP TPKT header\u0022, \u0022RDP negotiation\u0022, \u0022ET H.323 setup\u0022, \u0022Mumble ping\u0022, \u0022Minecraft varint handshake\u0022], \u0022pattern_ids\u0022: [\u0022pat-0348\u0022, \u0022pat-0352\u0022, \u0022pat-0868\u0022, \u0022pat-0768\u0022, \u0022pat-0554\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 52.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 50}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00226771a78868614c6768349c36da4591da\u0022, \u0022path_pattern_hash\u0022: \u00225dd788b551ee7afb63321e74cfc538f6\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 50}, \u0022payload_preview\u0022: \u0022\\u0003\\u0000\\u0000\\u000b\\u0006\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022request_sample\u0022: \u0022\\u0003\\u0000\\u0000\\u000b\\u0006\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0003\\u0000\\u0000\\u000b\\u0006\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0003\\u0000\\u0000\\u000b\\u0006\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0003\\u0000\\u0000\\u000b\\u0006\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab rdp_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022investigate\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00224470ce398a8a39bd8f65aab33be316e411b5881f\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0003\\u0000\\u0000\\u000b\\u0006\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd\u0022, \u0022attack_vector\u0022: \u0022rdp probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab rdp_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab rdp_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 50\/100 (Moyen) \u2014 MITRE TA0007 \u2014 confiance 100 % \u2014 via AWS ECS AGENT\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 52.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 50}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 50, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0348\u0022, \u0022pat-0352\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0348\u0022, \u0022pat-0352\u0022], \u0022recommended_action\u0022: \u0022investigate\u0022, \u0022recommended_action_label\u0022: \u0022Investiguer\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0003\\u0000\\u0000\\u000b\\u0006\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022rdp probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_investigate\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":11},{"id":9631761,"ip":"165.154.40.205","ts":"2026-06-19 04:13:21.000000","proto":"tcp","src_port":48300,"dst_port":4567,"service":"aws-ecs-agent","classification":"mssql_tds","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 16, \u0022payload_entropy\u0022: 2.5306390622295662, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 56.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 32, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0356\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0356\u0022], \u0022matched_patterns\u0022: [\u0022pat-0356\u0022, \u0022pat-0554\u0022], \u0022matched_pattern_names\u0022: [\u0022MSSQL TDS prelogin\u0022, \u0022Minecraft varint handshake\u0022], \u0022pattern_ids\u0022: [\u0022pat-0356\u0022, \u0022pat-0554\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 32}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00224128f0bf8d86360e67d6f2d54987a8fb\u0022, \u0022path_pattern_hash\u0022: \u0022285321e27377a1f85e5a231ca6cbffb2\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 32}, \u0022payload_preview\u0022: \u0022TNMP\\u0004\\u0000\\u0000\\u0000TNME\\u0000\\u0000\\u0004\\u0000\u0022, \u0022request_sample\u0022: \u0022TNMP\\u0004\\u0000\\u0000\\u0000TNME\\u0000\\u0000\\u0004\\u0000\u0022, \u0022payload_snippet\u0022: \u0022TNMP\\u0004\\u0000\\u0000\\u0000TNME\\u0000\\u0000\\u0004\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022TNMP\\u0004\\u0000\\u0000\\u0000TNME\\u0000\\u0000\\u0004\\u0000\u0022, \u0022payload_snippet\u0022: \u0022TNMP\\u0004\\u0000\\u0000\\u0000TNME\\u0000\\u0000\\u0004\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022e2b7522875ab05155642051f8fffe9443e8f50da\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022TNMP\\u0004\\u0000\\u0000\\u0000TNME\\u0000\\u0000\\u0004\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022TNMPTNME\u0022, \u0022attack_vector\u0022: \u0022mssql tds \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab mssql_tds \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 32\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 56.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 32}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 32, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0356\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0356\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022TNMP\\u0004\\u0000\\u0000\\u0000TNME\\u0000\\u0000\\u0004\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022mssql tds \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022TNMPTNME\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":16},{"id":9631755,"ip":"165.154.40.205","ts":"2026-06-19 04:13:18.000000","proto":"tcp","src_port":47448,"dst_port":4567,"service":"aws-ecs-agent","classification":"http_smuggling_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 223, \u0022payload_entropy\u0022: 5.2138020186451035, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 85.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 85.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 52, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab http_smuggling_probe \u00bb (signaux protocolaires) \u00b7 confiance 95%\u0022, \u0022confidence\u0022: 0.95, \u0022classification_confidence\u0022: 0.95, \u0022precision_score\u0022: 84, \u0022precision_signals\u0022: [\u0022pat-0842\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0842\u0022], \u0022matched_patterns\u0022: [\u0022pat-0842\u0022, \u0022pat-0384\u0022], \u0022matched_pattern_names\u0022: [\u0022CRS 921130 duplicate CL\u0022, \u0022SIP protocol\u0022], \u0022pattern_ids\u0022: [\u0022pat-0842\u0022, \u0022pat-0384\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 85.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 52}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 95.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022a45f037b8553e06cc139b7e55155fc44\u0022, \u0022path_pattern_hash\u0022: \u002206b55a159b5d265fc8976ebb0a005f8a\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 52}, \u0022payload_preview\u0022: \u0022INVITES sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42 \u0022, \u0022request_sample\u0022: \u0022INVITES sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42 OPTIONS\\r\\nMax-Forwards: 70\\r\\nContent-Length: 0\\r\\nContact: \u003Csip:nm@nm\u003E\\r\\nAccept: application\/sdp\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022INVITES sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022INVITES sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42 OPTIONS\\r\\nMax-Forwards: 70\\r\\nContent-Length: 0\\r\\nContact: \u003Csip:nm@nm\u003E\\r\\nAccept: application\/sdp\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022INVITES sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab http_smuggling_probe \u00bb (signaux protocolaires) \u00b7 confiance 95%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022web_injection\u0022], \u0022recommended_client_action\u0022: \u0022investigate\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00222c786ffea4f18f0e6ad9c564a4ef30ed372636e4\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022INVITES sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022INVITES sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42\u0022, \u0022attack_vector\u0022: \u0022http smuggling probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 95 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab http_smuggling_probe \u00bb (signaux protocolaires) \u00b7 confiance 95%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab http_smuggling_probe \u00bb (signaux protocolaires) \u00b7 confiance 95%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 52\/100 (Moyen) \u2014 MITRE TA0001 \u2014 confiance 95 % \u2014 via AWS ECS AGENT\u0022, \u0022confidence_pct\u0022: 95, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 85.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 52}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 52, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0842\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0842\u0022], \u0022recommended_action\u0022: \u0022investigate\u0022, \u0022recommended_action_label\u0022: \u0022Investiguer\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022INVITES sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022http smuggling probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022INVITES sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 95 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 95 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022ban_policy\u0022: \u0022advisory_investigate\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":223},{"id":9631751,"ip":"165.154.40.205","ts":"2026-06-19 04:13:15.000000","proto":"tcp","src_port":46546,"dst_port":4567,"service":"aws-ecs-agent","classification":"http_smuggling_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 223, \u0022payload_entropy\u0022: 5.197167462839961, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 85.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 85.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 52, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab http_smuggling_probe \u00bb (signaux protocolaires) \u00b7 confiance 95%\u0022, \u0022confidence\u0022: 0.95, \u0022classification_confidence\u0022: 0.95, \u0022precision_score\u0022: 84, \u0022precision_signals\u0022: [\u0022pat-0842\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0842\u0022], \u0022matched_patterns\u0022: [\u0022pat-0842\u0022, \u0022pat-0384\u0022, \u0022pat-0420\u0022, \u0022pat-0535\u0022], \u0022matched_pattern_names\u0022: [\u0022CRS 921130 duplicate CL\u0022, \u0022SIP protocol\u0022, \u0022HTTP OPTIONS method\u0022, \u0022SIP OPTIONS\u0022], \u0022pattern_ids\u0022: [\u0022pat-0842\u0022, \u0022pat-0384\u0022, \u0022pat-0420\u0022, \u0022pat-0535\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 85.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 52}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 95.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00220712a7f81d9d033f2caa8a8a90bbc4a8\u0022, \u0022path_pattern_hash\u0022: \u002206b55a159b5d265fc8976ebb0a005f8a\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 52}, \u0022payload_preview\u0022: \u0022OPTIONS sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42 \u0022, \u0022request_sample\u0022: \u0022OPTIONS sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42 OPTIONS\\r\\nMax-Forwards: 70\\r\\nContent-Length: 0\\r\\nContact: \u003Csip:nm@nm\u003E\\r\\nAccept: application\/sdp\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022OPTIONS sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022OPTIONS sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42 OPTIONS\\r\\nMax-Forwards: 70\\r\\nContent-Length: 0\\r\\nContact: \u003Csip:nm@nm\u003E\\r\\nAccept: application\/sdp\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022OPTIONS sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab http_smuggling_probe \u00bb (signaux protocolaires) \u00b7 confiance 95%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022web_injection\u0022], \u0022recommended_client_action\u0022: \u0022investigate\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022efc6f82bcf7c184c7873ff680e8284581d2256f7\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022OPTIONS sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022OPTIONS sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42\u0022, \u0022attack_vector\u0022: \u0022http smuggling probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 95 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab http_smuggling_probe \u00bb (signaux protocolaires) \u00b7 confiance 95%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab http_smuggling_probe \u00bb (signaux protocolaires) \u00b7 confiance 95%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 52\/100 (Moyen) \u2014 MITRE TA0001 \u2014 confiance 95 % \u2014 via AWS ECS AGENT\u0022, \u0022confidence_pct\u0022: 95, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 85.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 52}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 52, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0842\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0842\u0022], \u0022recommended_action\u0022: \u0022investigate\u0022, \u0022recommended_action_label\u0022: \u0022Investiguer\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022OPTIONS sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022http smuggling probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022OPTIONS sip:nm SIP\/2.0\\r\\nVia: SIP\/2.0\/TCP nm;branch=foo\\r\\nFrom: \u003Csip:nm@nm\u003E;tag=root\\r\\nTo: \u003Csip:nm2@nm2\u003E\\r\\nCall-ID: 50000\\r\\nCSeq: 42\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 95 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 95 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022ban_policy\u0022: \u0022advisory_investigate\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":223},{"id":9631747,"ip":"165.154.40.205","ts":"2026-06-19 04:13:12.000000","proto":"tcp","src_port":45772,"dst_port":4567,"service":"aws-ecs-agent","classification":"ldap_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 14, \u0022payload_entropy\u0022: 2.9852281360342516, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 54.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 54.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab ldap_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0859\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0859\u0022], \u0022matched_patterns\u0022: [\u0022pat-0859\u0022, \u0022pat-0554\u0022], \u0022matched_pattern_names\u0022: [\u0022ET LDAP anon bind\u0022, \u0022Minecraft varint handshake\u0022], \u0022pattern_ids\u0022: [\u0022pat-0859\u0022, \u0022pat-0554\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 54.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022548b3df94bdc85e8b94b0de75b5e0379\u0022, \u0022path_pattern_hash\u0022: \u002279ba87c92cce1f6abf5b6560fb8afdba\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u00220\\f\\u0002\\u0001\\u0001`\\u0007\\u0002\\u0001\\u0002\\u0004\\u0000\ufffd\\u0000\u0022, \u0022request_sample\u0022: \u00220\\f\\u0002\\u0001\\u0001`\\u0007\\u0002\\u0001\\u0002\\u0004\\u0000\ufffd\\u0000\u0022, \u0022payload_snippet\u0022: \u00220\\f\\u0002\\u0001\\u0001`\\u0007\\u0002\\u0001\\u0002\\u0004\\u0000\ufffd\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u00220\\f\\u0002\\u0001\\u0001`\\u0007\\u0002\\u0001\\u0002\\u0004\\u0000\ufffd\\u0000\u0022, \u0022payload_snippet\u0022: \u00220\\f\\u0002\\u0001\\u0001`\\u0007\\u0002\\u0001\\u0002\\u0004\\u0000\ufffd\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab ldap_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022f5c2b4eddcea38246a0edae9ca4a06a68793199f\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u00220\\f\\u0002\\u0001\\u0001`\\u0007\\u0002\\u0001\\u0002\\u0004\\u0000\ufffd\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u00220`\ufffd\u0022, \u0022attack_vector\u0022: \u0022ldap probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab ldap_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab ldap_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 54.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0859\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0859\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u00220\\f\\u0002\\u0001\\u0001`\\u0007\\u0002\\u0001\\u0002\\u0004\\u0000\ufffd\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022ldap probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u00220`\ufffd\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":14},{"id":9631746,"ip":"165.154.40.205","ts":"2026-06-19 04:13:09.000000","proto":"tcp","src_port":45058,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 51, \u0022payload_entropy\u0022: 3.7946877264252636, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0768\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022edc124f1d34ba290330abcac2736b204\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u00220\ufffd\\u0000\\u0000\\u0000-\\u0002\\u0001\\u0007c\ufffd\\u0000\\u0000\\u0000$\\u0004\\u0000\\n\\u0001\\u0000\\n\\u0001\\u0000\\u0002\\u0001\\u0000\\u0002\\u0001d\\u0001\\u0001\\u0000\ufffd\\u000bobjectClass0\ufffd\\u0000\\u0000\\u0000\\u0000\u0022, \u0022request_sample\u0022: \u00220\ufffd\\u0000\\u0000\\u0000-\\u0002\\u0001\\u0007c\ufffd\\u0000\\u0000\\u0000$\\u0004\\u0000\\n\\u0001\\u0000\\n\\u0001\\u0000\\u0002\\u0001\\u0000\\u0002\\u0001d\\u0001\\u0001\\u0000\ufffd\\u000bobjectClass0\ufffd\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u00220\ufffd\\u0000\\u0000\\u0000-\\u0002\\u0001\\u0007c\ufffd\\u0000\\u0000\\u0000$\\u0004\\u0000\\n\\u0001\\u0000\\n\\u0001\\u0000\\u0002\\u0001\\u0000\\u0002\\u0001d\\u0001\\u0001\\u0000\ufffd\\u000bobjectClass0\ufffd\\u0000\\u0000\\u0000\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u00220\ufffd\\u0000\\u0000\\u0000-\\u0002\\u0001\\u0007c\ufffd\\u0000\\u0000\\u0000$\\u0004\\u0000\\n\\u0001\\u0000\\n\\u0001\\u0000\\u0002\\u0001\\u0000\\u0002\\u0001d\\u0001\\u0001\\u0000\ufffd\\u000bobjectClass0\ufffd\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u00220\ufffd\\u0000\\u0000\\u0000-\\u0002\\u0001\\u0007c\ufffd\\u0000\\u0000\\u0000$\\u0004\\u0000\\n\\u0001\\u0000\\n\\u0001\\u0000\\u0002\\u0001\\u0000\\u0002\\u0001d\\u0001\\u0001\\u0000\ufffd\\u000bobjectClass0\ufffd\\u0000\\u0000\\u0000\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022f1d037d783f600cc6af962e9f8543e128f983c1e\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u00220\ufffd\\u0000\\u0000\\u0000-\\u0002\\u0001\\u0007c\ufffd\\u0000\\u0000\\u0000$\\u0004\\u0000\\n\\u0001\\u0000\\n\\u0001\\u0000\\u0002\\u0001\\u0000\\u0002\\u0001d\\u0001\\u0001\\u0000\ufffd\\u000bobjectClass0\ufffd\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u00220\ufffd-c\ufffd$\\n\\nd\ufffdobjectClass0\ufffd\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0768\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0768\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u00220\ufffd\\u0000\\u0000\\u0000-\\u0002\\u0001\\u0007c\ufffd\\u0000\\u0000\\u0000$\\u0004\\u0000\\n\\u0001\\u0000\\n\\u0001\\u0000\\u0002\\u0001\\u0000\\u0002\\u0001d\\u0001\\u0001\\u0000\ufffd\\u000bobjectClass0\ufffd\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u00220\ufffd-c\ufffd$\\n\\nd\ufffdobjectClass0\ufffd\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":51},{"id":9631744,"ip":"165.154.40.205","ts":"2026-06-19 04:13:06.000000","proto":"tcp","src_port":44352,"dst_port":4567,"service":"aws-ecs-agent","classification":"modbus_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 126, \u0022payload_entropy\u0022: 3.6365655435185062, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 33, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab modbus_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0357\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0357\u0022], \u0022matched_patterns\u0022: [\u0022pat-0357\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Modbus TCP header\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0357\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 33}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002298cb3978bd8d0583d0e6d69919db9eca\u0022, \u0022path_pattern_hash\u0022: \u00228ae4962b81dca47862d9dd3befc69030\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 33}, \u0022payload_snippet\u0022: \u0022\ufffd\ufffd\ufffd\ufffdversion\\u0000\\u0000\\u0000\\u0000\\u0000f\\u0000\\u0000\\u0000GH\ufffd\\u0013\\u0011\\u0001\\u0000\\r\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0006\\t=Z\\u0000\\u0000\\u0000\\u0000\\t\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffdYKI\\u000b \ufffd\\r\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0123A\ufffd\\u0004\ufffd\ufffd\\u0010\/Satoshi:0.15.1\/\\u0000\\u0000\\u0000\\u0000\\u0001\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\ufffd\ufffd\ufffd\ufffdversion\\u0000\\u0000\\u0000\\u0000\\u0000f\\u0000\\u0000\\u0000GH\ufffd\\u0013\\u0011\\u0001\\u0000\\r\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0006\\t=Z\\u0000\\u0000\\u0000\\u0000\\t\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffdYKI\\u000b \ufffd\\r\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0123A\ufffd\\u0004\ufffd\ufffd\\u0010\/Satoshi:0.15.1\/\\u0000\\u0000\\u0000\\u0000\\u0001\u0022, \u0022payload_snippet\u0022: \u0022\ufffd\ufffd\ufffd\ufffdversion\\u0000\\u0000\\u0000\\u0000\\u0000f\\u0000\\u0000\\u0000GH\ufffd\\u0013\\u0011\\u0001\\u0000\\r\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0006\\t=Z\\u0000\\u0000\\u0000\\u0000\\t\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffdYKI\\u000b \ufffd\\r\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0123A\ufffd\\u0004\ufffd\ufffd\\u0010\/Satoshi:0.15.1\/\\u0000\\u0000\\u0000\\u0000\\u0001\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab modbus_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022ics_probe\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002248e183c1ae0160b2a2594312d76fdf17a44ca3d7\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\ufffd\ufffd\ufffd\ufffdversion\\u0000\\u0000\\u0000\\u0000\\u0000f\\u0000\\u0000\\u0000GH\ufffd\\u0013\\u0011\\u0001\\u0000\\r\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0006\\t=Z\\u0000\\u0000\\u0000\\u0000\\t\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffdYKI\\u000b \ufffd\\r\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0123A\ufffd\\u0004\ufffd\ufffd\\u0010\/Satoshi:0.15.1\/\\u0000\\u0000\\u0000\\u0000\\u0001\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffd\ufffd\ufffdversionfGH\ufffd\\r\\t=Z\\t\ufffd\ufffdYKI \ufffd\\r\u0123A\ufffd\ufffd\ufffd\/Satoshi:0.15.1\/\u0022, \u0022attack_vector\u0022: \u0022modbus probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab modbus_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab modbus_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 33\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 33}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 33, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0357\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0357\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\ufffd\ufffd\ufffd\ufffdversion\\u0000\\u0000\\u0000\\u0000\\u0000f\\u0000\\u0000\\u0000GH\ufffd\\u0013\\u0011\\u0001\\u0000\\r\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0006\\t=Z\\u0000\\u0000\\u0000\\u0000\\t\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffdYKI\\u000b \ufffd\\r\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0123A\ufffd\\u0004\ufffd\ufffd\\u0010\/Satoshi:0.15.1\/\\u0000\\u0000\\u0000\\u0000\\u0001\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022modbus probe \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffd\ufffd\ufffdversionfGH\ufffd\\r\\t=Z\\t\ufffd\ufffdYKI \ufffd\\r\u0123A\ufffd\ufffd\ufffd\/Satoshi:0.15.1\/\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":126},{"id":9631743,"ip":"165.154.40.205","ts":"2026-06-19 04:13:03.000000","proto":"tcp","src_port":43520,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 9, \u0022payload_entropy\u0022: 3.169925001442312, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0577\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002239b37e76df338b7381ea8bb116701c98\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\\u0001default\\n\u0022, \u0022request_sample\u0022: \u0022\\u0001default\\n\u0022, \u0022payload_snippet\u0022: \u0022\\u0001default\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0001default\\n\u0022, \u0022payload_snippet\u0022: \u0022\\u0001default\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00223c6a52c3411f9f1fb717c9e5e731a0b63ce48b3b\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0001default\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022default\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0577\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0577\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0001default\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022default\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":9},{"id":9631736,"ip":"165.154.40.205","ts":"2026-06-19 04:13:00.000000","proto":"tcp","src_port":42786,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 53, \u0022payload_entropy\u0022: 4.704058897836964, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 34, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022d963b66fdf110d8684288a0719699a07d856b50c\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 34}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002208bd34a37b11f5c307f84418e0c2a579\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 34}, \u0022payload_preview\u0022: \u0022GET \/nice%20ports%2C\/Tri%6Eity.txt%2ebak HTTP\/1.0\\r\\n\\r\\n\u0022, \u0022request_sample\u0022: \u0022GET \/nice%20ports%2C\/Tri%6Eity.txt%2ebak HTTP\/1.0\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/nice%20ports%2C\/Tri%6Eity.txt%2ebak HTTP\/1.0\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/nice%20ports%2C\/Tri%6Eity.txt%2ebak HTTP\/1.0\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/nice%20ports%2C\/Tri%6Eity.txt%2ebak HTTP\/1.0\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022f117ad4d61520beffcdfd63b0c8574ae3de654a4\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/nice%20ports%2C\/Tri%6Eity.txt%2ebak HTTP\/1.0\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/nice%20ports%2C\/Tri%6Eity.txt%2ebak HTTP\/1.0\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 4 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 34\/100\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 34}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 34, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/nice%20ports%2C\/Tri%6Eity.txt%2ebak HTTP\/1.0\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/nice%20ports%2C\/Tri%6Eity.txt%2ebak HTTP\/1.0\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 4 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022http_get_probe\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022http_get_probe\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":53},{"id":9631730,"ip":"165.154.40.205","ts":"2026-06-19 04:12:57.000000","proto":"tcp","src_port":42076,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 12, \u0022payload_entropy\u0022: 0.8166890883150209, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0768\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022ad33d13d6bc3bd05c9957f130811a989\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022l\\u0000\\u000b\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022request_sample\u0022: \u0022l\\u0000\\u000b\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022l\\u0000\\u000b\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022l\\u0000\\u000b\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022l\\u0000\\u000b\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002202d4a96a2d2e5f1c24c21fc4cbd83358cd093591\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022l\\u0000\\u000b\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022l\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0768\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0768\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022l\\u0000\\u000b\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022l\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":12},{"id":9631726,"ip":"165.154.40.205","ts":"2026-06-19 04:12:54.000000","proto":"tcp","src_port":41262,"dst_port":4567,"service":"aws-ecs-agent","classification":"cloud_scanner","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u002232323020686f6e6579706f74206177735f6563735f6167656e7420726561647920706f72743d343536370d0a\u0022, \u0022emulator_response_len\u0022: 44, \u0022bytes_in\u0022: 168, \u0022payload_entropy\u0022: 4.517824025292926, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022app_proto\u0022: \u0022aws-ecs-agent\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022HK\u0022, \u0022dst_port\u0022: 4567, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 45.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022816265fc6d5545b4e2bffcaad02834271bfff300\u0022, \u0022event_fingerprint\u0022: \u0022ed5db39ce4a1ce0fda50382d1438797185e5f337\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0771\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022HK\u0022, \u0022asn\u0022: 135377, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00224c8b954e7bc1bc076c8d1bd64820e67f\u0022, \u0022path_pattern_hash\u0022: \u0022d7b9b7079445a015d8a6ef804f129303\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000\ufffd\ufffdSMBr\\u0000\\u0000\\u0000\\u0000\\b\\u0001@\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000@\\u0006\\u0000\\u0000\\u0001\\u0000\\u0000\ufffd\\u0000\\u0002PC NETWORK PROGRAM 1.0\\u0000\\u0002MICROSOFT NETWORKS 1.03\\u0000\\u0002MICROSOFT NETWORKS 3.0\\u0000\\u0002LANMAN1.0\\u0000\\u0002LM1.\u0022, \u0022request_sample\u0022: \u0022\\u0000\\u0000\\u0000\ufffd\ufffdSMBr\\u0000\\u0000\\u0000\\u0000\\b\\u0001@\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000@\\u0006\\u0000\\u0000\\u0001\\u0000\\u0000\ufffd\\u0000\\u0002PC NETWORK PROGRAM 1.0\\u0000\\u0002MICROSOFT NETWORKS 1.03\\u0000\\u0002MICROSOFT NETWORKS 3.0\\u0000\\u0002LANMAN1.0\\u0000\\u0002LM1.2X002\\u0000\\u0002Samba\\u0000\\u0002NT LANMAN 1.0\\u0000\\u0002NT LM 0.12\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\\u0000\\u0000\ufffd\ufffdSMBr\\u0000\\u0000\\u0000\\u0000\\b\\u0001@\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000@\\u0006\\u0000\\u0000\\u0001\\u0000\\u0000\ufffd\\u0000\\u0002PC NETWORK PROGRAM 1.0\\u0000\\u0002MICROSOFT NETWORKS 1.03\\u0000\\u0002MICROSOFT NETWORKS 3.0\\u0000\\u0002LANMAN1.0\\u0000\\u0002LM1.\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0000\\u0000\\u0000\ufffd\ufffdSMBr\\u0000\\u0000\\u0000\\u0000\\b\\u0001@\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000@\\u0006\\u0000\\u0000\\u0001\\u0000\\u0000\ufffd\\u0000\\u0002PC NETWORK PROGRAM 1.0\\u0000\\u0002MICROSOFT NETWORKS 1.03\\u0000\\u0002MICROSOFT NETWORKS 3.0\\u0000\\u0002LANMAN1.0\\u0000\\u0002LM1.2X002\\u0000\\u0002Samba\\u0000\\u0002NT LANMAN 1.0\\u0000\\u0002NT LM 0.12\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0000\\u0000\\u0000\ufffd\ufffdSMBr\\u0000\\u0000\\u0000\\u0000\\b\\u0001@\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000@\\u0006\\u0000\\u0000\\u0001\\u0000\\u0000\ufffd\\u0000\\u0002PC NETWORK PROGRAM 1.0\\u0000\\u0002MICROSOFT NETWORKS 1.03\\u0000\\u0002MICROSOFT NETWORKS 3.0\\u0000\\u0002LANMAN1.0\\u0000\\u0002LM1.\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022, \u0022cloud_metadata_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00224631814ec3a21e339cdf66a17740a05f83d2ce2c\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000\ufffd\ufffdSMBr\\u0000\\u0000\\u0000\\u0000\\b\\u0001@\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000@\\u0006\\u0000\\u0000\\u0001\\u0000\\u0000\ufffd\\u0000\\u0002PC NETWORK PROGRAM 1.0\\u0000\\u0002MICROSOFT NETWORKS 1.03\\u0000\\u0002MICROSOFT NETWORKS 3.0\\u0000\\u0002LANMAN1.0\\u0000\\u0002LM1.\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffdSMBr@@\ufffdPC NETWORK PROGRAM 1.0MICROSOFT NETWORKS 1.03MICROSOFT NETWORKS 3.0LANMAN1.0LM1.\u0022, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab cloud_scanner \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 45.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022, \u0022dst_port\u0022: 4567, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0771\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0771\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0000\\u0000\\u0000\ufffd\ufffdSMBr\\u0000\\u0000\\u0000\\u0000\\b\\u0001@\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000@\\u0006\\u0000\\u0000\\u0001\\u0000\\u0000\ufffd\\u0000\\u0002PC NETWORK PROGRAM 1.0\\u0000\\u0002MICROSOFT NETWORKS 1.03\\u0000\\u0002MICROSOFT NETWORKS 3.0\\u0000\\u0002LANMAN1.0\\u0000\\u0002LM1.\u0022, \u0022port\u0022: 4567, \u0022service\u0022: \u0022aws-ecs-agent\u0022, \u0022service_label_fr\u0022: \u0022AWS ECS AGENT\u0022}, \u0022attack_vector\u0022: \u0022cloud scanner \u00b7 via AWS ECS AGENT:4567 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffdSMBr@@\ufffdPC NETWORK PROGRAM 1.0MICROSOFT NETWORKS 1.03MICROSOFT NETWORKS 3.0LANMAN1.0LM1.\u0022, \u0022target_port_label\u0022: \u00224567 \u00b7 AWS ECS AGENT\u0022, \u0022emulator_service\u0022: \u0022aws-ecs-agent\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022aws_ecs_agent\u0022, \u0022service_banner\u0022: \u0022honeypot-aws-ecs-agent\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224567\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022aws_ecs_agent_emulated\u0022, \u0022aws_ecs_agent_payload\u0022, \u0022net_cloud_scanner\u0022]","anomalies":"[]","severity":5,"bytes_in":168}],"total_events":135}