{"ip":"184.105.247.195","exported_at":"2026-06-17T06:10:40+00:00","period_days":30,"metrics":{"events7d":11,"distinct_ports":8,"distinct_classifications":4,"max_severity":8,"last_sensor_id":"paris-1","max_waf_score":16,"max_risk_score":100,"attack_stage":"probe","attack_chain_stage":"discovery","threat_family":["scanner"],"recommended_action":"monitor","confidence":0.49,"risk_breakdown":{"waf":8,"classification":32,"behavior":0,"geo":0,"protocol":30,"novelty":15},"mitre_tactics":["TA0007","TA0001"],"mitre_technique":"TA0007","top_mitre_technique":"TA0007","top_mitre_count":11,"executive_one_liner_fr":"Activit\u00e9 suspecte \u00b7 risque 35\/100","campaign_hint_fr":null,"confidence_breakdown":{"waf":8,"classification":32,"behavior":0,"geo":0,"protocol":30,"novelty":15,"risk_score":35},"persona_hostname":"mail.sensor-1.internal","correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":49,"confidence_hint_fr":"Confiance mod\u00e9r\u00e9e \u2014 signal unique","sensor_role_label_fr":"Renseignement menaces","tags_summary_labels_fr":["pat-0369"],"tags_summary":["pat-0369"],"attack_vector":"postgres probe \u00b7 via HTTPS ALT 20443:20443 \u00b7 (sonde \/ probe)","protocol_details":{"payload_preview":"\u0016\u0003\u0001\u0000{\u0001\u0000\u0000w\u0003\u0003J\ufffd\ufffd\ufffdd\u02b7A\ufffd\ufffdc%LDP?\u0014\ufffd\ufffd?TT\u001ea\ufffdT\ufffd\\\ufffd%8\u0000\u0000\u001a\ufffd\/\ufffd+\ufffd\u0011\ufffd\u0007\ufffd\u0013\ufffd\t\ufffd\u0014\ufffd\n\u0000\u0005\u0000\/\u00005\ufffd\u0012\u0000\n\u0001\u0000\u00004\u0000\u0005\u0000\u0005\u0001\u0000\u0000\u0000\u0000\u0000\n\u0000\b\u0000\u0006\u0000\u0017\u0000\u0018\u0000\u0019\u0000\u000b\u0000\u0002\u0001\u0000\u0000\r\u0000\u0010\u0000\u000e\u0004\u0001\u0004\u0003\u0002\u0001\u0002\u0003\u0004\u0001\u0005\u0001\u0006\u0001\ufffd\u0001\u0000\u0001\u0000","tls_ja3":"cba7f34191ef2379c1325641f6c6c4f4","tls_ja4":"a3a5f53d3656a0df675e8aa020d5979e","port":20443,"service":"https-alt-20443","service_label_fr":"HTTPS ALT 20443"},"protocol_summary_fr":"JA3 cba7f34191ef2379 \u00b7 Payload \u0016\u0003\u0001\u0000{\u0001\u0000\u0000w\u0003\u0003J\ufffd\ufffd\ufffdd\u02b7A\ufffd\ufffdc%LDP?\u0014\ufffd\ufffd?TT\u001ea\ufffdT\ufffd\\\ufffd%8\u0000\u0000\u001a\ufffd\/\ufffd+\ufffd\u0011\ufffd\u0007\ufffd\u0013\ufffd\t\ufffd\u0014\ufffd\n\u0000\u0005\u2026 \u00b7 HTTPS ALT 20443:20443","evidence_snippet":"{wJ\ufffd\ufffd\ufffdd\u02b7A\ufffd\ufffdc%LDP?\ufffd\ufffd?TTa\ufffdT\ufffd\\\ufffd%8\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\t\ufffd\ufffd\n\/5\ufffd\n4\n\r\ufffd","target_port_label":"20443 \u00b7 HTTPS ALT 20443","emulator_service":"https-alt-20443","confidence_reason":"Confiance 49 % \u2014 Motif catalogue confirm\u00e9","classification_reason":"Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%","classification_reason_label_fr":"Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%","confidence_factors_fr":"Confiance 49 % \u2014 Score WAF 8","payload_preview":"{wJ\ufffd\ufffd\ufffdd\u02b7A\ufffd\ufffdc%LDP?\ufffd\ufffd?TTa\ufffdT\ufffd\\\ufffd%8\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\t\ufffd\ufffd\n\/5\ufffd\n4\n\r\ufffd"},"events":[{"id":9454345,"ip":"184.105.247.195","ts":"2026-06-17 05:22:39.000000","proto":"tcp","src_port":21272,"dst_port":20443,"service":"https-alt-20443","classification":"postgres_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a5365727665723a204170616368652f322e342e35370d0a436f6e74656e742d4c656e6774683a20320d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a4f4b\u0022, \u0022emulator_response_len\u0022: 82, \u0022bytes_in\u0022: 128, \u0022payload_entropy\u0022: 4.861264444322512, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022https-alt-20443\u0022, \u0022app_proto\u0022: \u0022https-alt-20443\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 20443, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022b9ff0d5ba6597294c5519a4ed0a629f58fb4896a\u0022, \u0022event_fingerprint\u0022: \u0022a9ec10e4a5e77a82c4a7a417b7d7469fc1f1ab24\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0369\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0369\u0022], \u0022matched_patterns\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022PostgreSQL startup\u0022, \u0022Minecraft varint handshake\u0022, \u0022SOCKS5 greeting\u0022, \u0022SIP TLS ClientHello\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022https-alt-20443\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022bfe4b01ca66efd9e0ede56ed560c93ed\u0022, \u0022path_pattern_hash\u0022: \u002280f3c71fe26f36a0a9399108643f66c5\u0022, \u0022ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 13, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022}, \u0022tls_ja3_hash\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja3\u0022: \u0022771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0\u0022, \u0022tls_ja4_hash\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_ja4\u0022: \u0022t13d0113_ad3470b4f447_40d2e578a3e2\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 13, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022, \u0022target_context\u0022: {\u0022dst_port\u0022: 20443, \u0022service\u0022: \u0022https-alt-20443\u0022, \u0022service_name\u0022: \u0022https-alt-20443\u0022, \u0022risk_score\u0022: 35}, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003J\ufffd\ufffd\ufffdd\u02b7A\ufffd\ufffdc%LDP?\\u0014\ufffd\ufffd?TT\\u001ea\ufffdT\ufffd\\\\\ufffd%8\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003J\ufffd\ufffd\ufffdd\u02b7A\ufffd\ufffdc%LDP?\\u0014\ufffd\ufffd?TT\\u001ea\ufffdT\ufffd\\\\\ufffd%8\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003J\ufffd\ufffd\ufffdd\u02b7A\ufffd\ufffdc%LDP?\\u0014\ufffd\ufffd?TT\\u001ea\ufffdT\ufffd\\\\\ufffd%8\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022242b5e6e6c7cb227b7f94406abd94eebd9bde3f2\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003J\ufffd\ufffd\ufffdd\u02b7A\ufffd\ufffdc%LDP?\\u0014\ufffd\ufffd?TT\\u001ea\ufffdT\ufffd\\\\\ufffd%8\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022tls_ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022port\u0022: 20443, \u0022service\u0022: \u0022https-alt-20443\u0022, \u0022service_label_fr\u0022: \u0022HTTPS ALT 20443\u0022}, \u0022evidence_snippet\u0022: \u0022{wJ\ufffd\ufffd\ufffdd\u02b7A\ufffd\ufffdc%LDP?\ufffd\ufffd?TTa\ufffdT\ufffd\\\\\ufffd%8\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\\t\ufffd\ufffd\\n\/5\ufffd\\n4\\n\\r\ufffd\u0022, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via HTTPS ALT 20443:20443 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002220443 \u00b7 HTTPS ALT 20443\u0022, \u0022emulator_service\u0022: \u0022https-alt-20443\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 35\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 35, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022https-alt-20443\u0022, \u0022service_label_fr\u0022: \u0022HTTPS ALT 20443\u0022, \u0022dst_port\u0022: 20443, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0369\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0369\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-https-alt-20443\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003J\ufffd\ufffd\ufffdd\u02b7A\ufffd\ufffdc%LDP?\\u0014\ufffd\ufffd?TT\\u001ea\ufffdT\ufffd\\\\\ufffd%8\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022tls_ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022port\u0022: 20443, \u0022service\u0022: \u0022https-alt-20443\u0022, \u0022service_label_fr\u0022: \u0022HTTPS ALT 20443\u0022}, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via HTTPS ALT 20443:20443 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022{wJ\ufffd\ufffd\ufffdd\u02b7A\ufffd\ufffdc%LDP?\ufffd\ufffd?TTa\ufffdT\ufffd\\\\\ufffd%8\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\\t\ufffd\ufffd\\n\/5\ufffd\\n4\\n\\r\ufffd\u0022, \u0022target_port_label\u0022: \u002220443 \u00b7 HTTPS ALT 20443\u0022, \u0022emulator_service\u0022: \u0022https-alt-20443\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022meta_truncated\u0022: true, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022https_alt_20443\u0022, \u0022service_banner\u0022: \u0022honeypot-https-alt-20443\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002220443\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022tls_clienthello\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_clienthello\u0022]","anomalies":"[]","severity":3,"bytes_in":128},{"id":9443468,"ip":"184.105.247.195","ts":"2026-06-17 02:06:40.000000","proto":"tcp","src_port":30230,"dst_port":8060,"service":"http-alt-8060","classification":"postgres_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a5365727665723a204170616368652f322e342e35370d0a436f6e74656e742d4c656e6774683a20320d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a4f4b\u0022, \u0022emulator_response_len\u0022: 82, \u0022bytes_in\u0022: 128, \u0022payload_entropy\u0022: 4.882787002933164, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http-alt-8060\u0022, \u0022app_proto\u0022: \u0022http-alt-8060\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 8060, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 0.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c5657d50162ced0a633bc84378aadefe48751ee2\u0022, \u0022event_fingerprint\u0022: \u00229fa63a7d4d5c58347a0ca1e629c489216a9833f2\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0369\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0369\u0022], \u0022matched_patterns\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022PostgreSQL startup\u0022, \u0022Minecraft varint handshake\u0022, \u0022SOCKS5 greeting\u0022, \u0022SIP TLS ClientHello\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http-alt-8060\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022be093bda458728a6ba8c0a660e24d980\u0022, \u0022path_pattern_hash\u0022: \u002280f3c71fe26f36a0a9399108643f66c5\u0022, \u0022ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 13, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022}, \u0022tls_ja3_hash\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja3\u0022: \u0022771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0\u0022, \u0022tls_ja4_hash\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_ja4\u0022: \u0022t13d0113_ad3470b4f447_40d2e578a3e2\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 13, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022, \u0022target_context\u0022: {\u0022dst_port\u0022: 8060, \u0022service\u0022: \u0022http-alt-8060\u0022, \u0022service_name\u0022: \u0022http-alt-8060\u0022, \u0022risk_score\u0022: 35}, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003j\\u000f\ufffd\ufffd\ufffd\ufffd~\ufffd\ufffd\u0469\\\u0022\ufffd\\u0015\ufffd\ufffd3\\u001c$\ufffd A\ufffd\ufffd\ufffd\u003C\\u0013$\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003j\\u000f\ufffd\ufffd\ufffd\ufffd~\ufffd\ufffd\u0469\\\u0022\ufffd\\u0015\ufffd\ufffd3\\u001c$\ufffd A\ufffd\ufffd\ufffd\u003C\\u0013$\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003j\\u000f\ufffd\ufffd\ufffd\ufffd~\ufffd\ufffd\u0469\\\u0022\ufffd\\u0015\ufffd\ufffd3\\u001c$\ufffd A\ufffd\ufffd\ufffd\u003C\\u0013$\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022cf4f35a2859ce883fafabc8d38335dd0b47992ff\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003j\\u000f\ufffd\ufffd\ufffd\ufffd~\ufffd\ufffd\u0469\\\u0022\ufffd\\u0015\ufffd\ufffd3\\u001c$\ufffd A\ufffd\ufffd\ufffd\u003C\\u0013$\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022tls_ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022port\u0022: 8060, \u0022service\u0022: \u0022http-alt-8060\u0022, \u0022service_label_fr\u0022: \u0022HTTP ALT 8060\u0022}, \u0022evidence_snippet\u0022: \u0022{wj\ufffd\ufffd\ufffd\ufffd~\ufffd\ufffd\u0469\\\u0022\ufffd\ufffd\ufffd3$\ufffd A\ufffd\ufffd\ufffd\u003C$\ufffd\ufffd\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\\t\ufffd\ufffd\\n\/5\ufffd\\n4\\n\\r\ufffd\u0022, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via HTTP ALT 8060:8060 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00228060 \u00b7 HTTP ALT 8060\u0022, \u0022emulator_service\u0022: \u0022http-alt-8060\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 35\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 35, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022http-alt-8060\u0022, \u0022service_label_fr\u0022: \u0022HTTP ALT 8060\u0022, \u0022dst_port\u0022: 8060, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0369\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0369\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http-alt-8060\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003j\\u000f\ufffd\ufffd\ufffd\ufffd~\ufffd\ufffd\u0469\\\u0022\ufffd\\u0015\ufffd\ufffd3\\u001c$\ufffd A\ufffd\ufffd\ufffd\u003C\\u0013$\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022tls_ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022port\u0022: 8060, \u0022service\u0022: \u0022http-alt-8060\u0022, \u0022service_label_fr\u0022: \u0022HTTP ALT 8060\u0022}, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via HTTP ALT 8060:8060 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022{wj\ufffd\ufffd\ufffd\ufffd~\ufffd\ufffd\u0469\\\u0022\ufffd\ufffd\ufffd3$\ufffd A\ufffd\ufffd\ufffd\u003C$\ufffd\ufffd\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\\t\ufffd\ufffd\\n\/5\ufffd\\n4\\n\\r\ufffd\u0022, \u0022target_port_label\u0022: \u00228060 \u00b7 HTTP ALT 8060\u0022, \u0022emulator_service\u0022: \u0022http-alt-8060\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022meta_truncated\u0022: true, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http_alt_8060\u0022, \u0022service_banner\u0022: \u0022honeypot-http-alt-8060\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228060\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022tls_clienthello\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_clienthello\u0022]","anomalies":"[]","severity":3,"bytes_in":128},{"id":9440562,"ip":"184.105.247.195","ts":"2026-06-17 01:20:08.000000","proto":"tcp","src_port":17260,"dst_port":2083,"service":"cpanel-ssl","classification":"postgres_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a5365727665723a206370737276642f31312e3131300d0a436f6e74656e742d547970653a20746578742f68746d6c0d0a436f6e74656e742d4c656e6774683a2033380d0a0d0a3c68746d6c3e3c626f64793e6350616e656c204c6f67696e3c2f626f64793e3c2f68746d6c3e\u0022, \u0022emulator_response_len\u0022: 125, \u0022bytes_in\u0022: 128, \u0022payload_entropy\u0022: 4.830014444322512, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022cpanel-ssl\u0022, \u0022app_proto\u0022: \u0022cpanel-ssl\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 2083, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00224cc54c7fcd5f1e5ebb94393f5b67f30e90170090\u0022, \u0022event_fingerprint\u0022: \u002280d2812b66b9080b0842670f25ce9d4d3386dae1\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0369\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0369\u0022], \u0022matched_patterns\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022PostgreSQL startup\u0022, \u0022Minecraft varint handshake\u0022, \u0022SOCKS5 greeting\u0022, \u0022SIP TLS ClientHello\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022cpanel-ssl\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00227ea9698cd6b49679dd7c5e620710f63b\u0022, \u0022path_pattern_hash\u0022: \u002280f3c71fe26f36a0a9399108643f66c5\u0022, \u0022ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 13, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022}, \u0022tls_ja3_hash\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja3\u0022: \u0022771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0\u0022, \u0022tls_ja4_hash\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_ja4\u0022: \u0022t13d0113_ad3470b4f447_40d2e578a3e2\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 13, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022, \u0022target_context\u0022: {\u0022dst_port\u0022: 2083, \u0022service\u0022: \u0022cpanel-ssl\u0022, \u0022service_name\u0022: \u0022cpanel-ssl\u0022, \u0022risk_score\u0022: 35}, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\ufffdp\ufffdPy\ufffd\/AK3\ufffd\\u0013\ufffd\\u0011%\ufffd\ufffd\u07d7\ufffd\ufffd\ufffdI3\u06b6\ufffd\ufffd7\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\ufffdp\ufffdPy\ufffd\/AK3\ufffd\\u0013\ufffd\\u0011%\ufffd\ufffd\u07d7\ufffd\ufffd\ufffdI3\u06b6\ufffd\ufffd7\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\ufffdp\ufffdPy\ufffd\/AK3\ufffd\\u0013\ufffd\\u0011%\ufffd\ufffd\u07d7\ufffd\ufffd\ufffdI3\u06b6\ufffd\ufffd7\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022e337c7ee7e1bd6430539507e69aaec61edf13d81\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\ufffdp\ufffdPy\ufffd\/AK3\ufffd\\u0013\ufffd\\u0011%\ufffd\ufffd\u07d7\ufffd\ufffd\ufffdI3\u06b6\ufffd\ufffd7\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022tls_ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022port\u0022: 2083, \u0022service\u0022: \u0022cpanel-ssl\u0022, \u0022service_label_fr\u0022: \u0022CPANEL SSL\u0022}, \u0022evidence_snippet\u0022: \u0022{w\ufffd\ufffdp\ufffdPy\ufffd\/AK3\ufffd\ufffd%\ufffd\ufffd\u07d7\ufffd\ufffd\ufffdI3\u06b6\ufffd\ufffd7\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\\t\ufffd\ufffd\\n\/5\ufffd\\n4\\n\\r\ufffd\u0022, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via CPANEL SSL:2083 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00222083 \u00b7 CPANEL SSL\u0022, \u0022emulator_service\u0022: \u0022cpanel-ssl\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 35\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 35, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022cpanel-ssl\u0022, \u0022service_label_fr\u0022: \u0022CPANEL SSL\u0022, \u0022dst_port\u0022: 2083, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0369\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0369\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-cpanel-ssl\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\ufffdp\ufffdPy\ufffd\/AK3\ufffd\\u0013\ufffd\\u0011%\ufffd\ufffd\u07d7\ufffd\ufffd\ufffdI3\u06b6\ufffd\ufffd7\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022tls_ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022port\u0022: 2083, \u0022service\u0022: \u0022cpanel-ssl\u0022, \u0022service_label_fr\u0022: \u0022CPANEL SSL\u0022}, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via CPANEL SSL:2083 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022{w\ufffd\ufffdp\ufffdPy\ufffd\/AK3\ufffd\ufffd%\ufffd\ufffd\u07d7\ufffd\ufffd\ufffdI3\u06b6\ufffd\ufffd7\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\\t\ufffd\ufffd\\n\/5\ufffd\\n4\\n\\r\ufffd\u0022, \u0022target_port_label\u0022: \u00222083 \u00b7 CPANEL SSL\u0022, \u0022emulator_service\u0022: \u0022cpanel-ssl\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022meta_truncated\u0022: true, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022cpanel_ssl\u0022, \u0022service_banner\u0022: \u0022honeypot-cpanel-ssl\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00222083\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022cpanel_ssl_emulated\u0022, \u0022net_cpanel_probe\u0022, \u0022tls_clienthello\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022cpanel_ssl_emulated\u0022, \u0022net_cpanel_probe\u0022, \u0022tls_clienthello\u0022]","anomalies":"[]","severity":3,"bytes_in":128},{"id":9390144,"ip":"184.105.247.195","ts":"2026-06-16 13:57:57.000000","proto":"tcp","src_port":47922,"dst_port":9001,"service":"tor-or","classification":"tor_exit_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022030000000000000000\u0022, \u0022emulator_response_len\u0022: 9, \u0022bytes_in\u0022: 202, \u0022payload_entropy\u0022: 5.39411354281705, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022tor-or\u0022, \u0022app_proto\u0022: \u0022tor-or\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 9001, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 62.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 3.9, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 62.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022d967b0275d13a566643f776c2f2ca13b50a86244\u0022, \u0022event_fingerprint\u0022: \u00222bc74a66a243c40126697f519e65200a159d147e\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab tor_exit_probe \u00bb (signaux protocolaires) \u00b7 confiance 46%\u0022, \u0022confidence\u0022: 0.46, \u0022classification_confidence\u0022: 0.46, \u0022precision_score\u0022: 55, \u0022precision_signals\u0022: [\u0022INT-TOR-exit-hint\u0022], \u0022kb_rule_ids\u0022: [\u0022INT-TOR-exit-hint\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 62.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022tor-or\u0022, \u0022risk_confidence_factor\u0022: 46.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00226c75d3aec91ebd1b2698850b4835f2b8\u0022, \u0022path_pattern_hash\u0022: \u0022d2d40d620e587c49ef0af866b893b1d5\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 9001, \u0022service\u0022: \u0022tor-or\u0022, \u0022service_name\u0022: \u0022tor-or\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9001\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9001\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/125.0.0.0 Safari\/537.36\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9001\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9001\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/125.0.0.0 Safari\/537.36\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9001\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab tor_exit_probe \u00bb (signaux protocolaires) \u00b7 confiance 46%\u0022}, \u0022attack_stage\u0022: \u0022c2\u0022, \u0022mitre_tactics\u0022: [\u0022TA0011\u0022], \u0022mitre\u0022: \u0022TA0011\u0022, \u0022threat_family\u0022: [\u0022botnet\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022fc6a43a92b619c7426b65b543625a79a93c3d2c8\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9001\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022port\u0022: 9001, \u0022service\u0022: \u0022tor-or\u0022, \u0022service_label_fr\u0022: \u0022TOR OR\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9001\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022attack_vector\u0022: \u0022tor exit probe \u00b7 via TOR OR:9001 \u00b7 (commande \u0026 contr\u00f4le)\u0022, \u0022target_port_label\u0022: \u00229001 \u00b7 TOR OR\u0022, \u0022emulator_service\u0022: \u0022tor-or\u0022, \u0022confidence_reason\u0022: \u0022Confiance 46 % \u2014 6 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab tor_exit_probe \u00bb (signaux protocolaires) \u00b7 confiance 46%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab tor_exit_probe \u00bb (signaux protocolaires) \u00b7 confiance 46%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0011 \u2014 confiance 46 % \u2014 via TOR OR\u0022, \u0022confidence_pct\u0022: 46, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 62.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022c2\u0022, \u0022attack_stage_label\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022attack_chain_stage\u0022: \u0022command_and_control\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022tor-or\u0022, \u0022service_label_fr\u0022: \u0022TOR OR\u0022, \u0022dst_port\u0022: 9001, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022INT-TOR-exit-hint\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022Tor Exit Hint\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0011\u0022, \u0022mitre_technique\u0022: \u0022TA0011\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-tor-or\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9001\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022port\u0022: 9001, \u0022service\u0022: \u0022tor-or\u0022, \u0022service_label_fr\u0022: \u0022TOR OR\u0022}, \u0022attack_vector\u0022: \u0022tor exit probe \u00b7 via TOR OR:9001 \u00b7 (commande \u0026 contr\u00f4le)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9001\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022target_port_label\u0022: \u00229001 \u00b7 TOR OR\u0022, \u0022emulator_service\u0022: \u0022tor-or\u0022, \u0022confidence_reason\u0022: \u0022Confiance 46 % \u2014 6 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 46 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022command_and_control\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022tor_or\u0022, \u0022service_banner\u0022: \u0022honeypot-tor-or\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00229001\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022command_and_control\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_tor_probe\u0022, \u0022tor_exit_probe\u0022, \u0022tor_or_emulated\u0022, \u0022tor_or_payload\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_tor_probe\u0022, \u0022tor_exit_probe\u0022, \u0022tor_or_emulated\u0022, \u0022tor_or_payload\u0022]","anomalies":"[]","severity":7,"bytes_in":202},{"id":9358895,"ip":"184.105.247.195","ts":"2026-06-16 07:37:17.000000","proto":"tcp","src_port":27904,"dst_port":5985,"service":"winrm","classification":"winrm_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e312034303120556e617574686f72697a65640d0a5757572d41757468656e7469636174653a204e65676f74696174650d0a436f6e74656e742d4c656e6774683a20300d0a0d0a\u0022, \u0022emulator_response_len\u0022: 77, \u0022bytes_in\u0022: 202, \u0022payload_entropy\u0022: 5.415097854487978, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022winrm\u0022, \u0022app_proto\u0022: \u0022winrm\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 5985, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 62.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 46.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 2.1, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 62.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 46.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 31, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002241fa5d82cf5e704b60baf3241e133cb99d9fe750\u0022, \u0022event_fingerprint\u0022: \u002269c3741eda286def0bdd9c17863648ff58bc3b2f\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab winrm_probe \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 62.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 46.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 31}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022winrm\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022244197015987202ab481937075f41687\u0022, \u0022path_pattern_hash\u0022: \u0022a98d2328dfdc853a4ac94ea7611b67e5\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 5985, \u0022service\u0022: \u0022winrm\u0022, \u0022service_name\u0022: \u0022winrm\u0022, \u0022risk_score\u0022: 31}, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:5985\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:5985\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/109.0.0.0 Safari\/537.36\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:5985\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:5985\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/109.0.0.0 Safari\/537.36\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:5985\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab winrm_probe \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00220ffbeacae8c6b42e1cfc34593f9c2acd10f9e11f\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:5985\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022port\u0022: 5985, \u0022service\u0022: \u0022winrm\u0022, \u0022service_label_fr\u0022: \u0022WINRM\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:5985\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022attack_vector\u0022: \u0022winrm probe \u00b7 via WINRM:5985 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00225985 \u00b7 WINRM\u0022, \u0022emulator_service\u0022: \u0022winrm\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab winrm_probe \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab winrm_probe \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 31\/100\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 62.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 46.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 31}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 31, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022winrm\u0022, \u0022service_label_fr\u0022: \u0022WINRM\u0022, \u0022dst_port\u0022: 5985, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-winrm\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:5985\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022port\u0022: 5985, \u0022service\u0022: \u0022winrm\u0022, \u0022service_label_fr\u0022: \u0022WINRM\u0022}, \u0022attack_vector\u0022: \u0022winrm probe \u00b7 via WINRM:5985 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:5985\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022target_port_label\u0022: \u00225985 \u00b7 WINRM\u0022, \u0022emulator_service\u0022: \u0022winrm\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022winrm\u0022, \u0022service_banner\u0022: \u0022honeypot-winrm\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00225985\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_winrm_probe\u0022, \u0022winrm_emulated\u0022, \u0022winrm_payload\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_winrm_probe\u0022, \u0022winrm_emulated\u0022, \u0022winrm_payload\u0022]","anomalies":"[]","severity":7,"bytes_in":202},{"id":9333445,"ip":"184.105.247.195","ts":"2026-06-16 03:00:16.000000","proto":"tcp","src_port":29940,"dst_port":4848,"service":"glassfish-admin","classification":"postgres_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a5365727665723a204170616368652f322e342e35370d0a436f6e74656e742d4c656e6774683a20320d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a4f4b\u0022, \u0022emulator_response_len\u0022: 82, \u0022bytes_in\u0022: 128, \u0022payload_entropy\u0022: 4.817698887112719, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022glassfish-admin\u0022, \u0022app_proto\u0022: \u0022glassfish-admin\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 4848, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022a681bdab5e03e0b5e161a796cd1f67b37c52aabc\u0022, \u0022event_fingerprint\u0022: \u00229eb4a5bed64f235435fc220a3c7d0cc6870acffc\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0369\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0369\u0022], \u0022matched_patterns\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022PostgreSQL startup\u0022, \u0022Minecraft varint handshake\u0022, \u0022SOCKS5 greeting\u0022, \u0022SIP TLS ClientHello\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022glassfish-admin\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00222570d01493546fc44bfe13b3f97646a7\u0022, \u0022path_pattern_hash\u0022: \u002280f3c71fe26f36a0a9399108643f66c5\u0022, \u0022ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 13, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022}, \u0022tls_ja3_hash\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja3\u0022: \u0022771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0\u0022, \u0022tls_ja4_hash\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_ja4\u0022: \u0022t13d0113_ad3470b4f447_40d2e578a3e2\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 13, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022, \u0022target_context\u0022: {\u0022dst_port\u0022: 4848, \u0022service\u0022: \u0022glassfish-admin\u0022, \u0022service_name\u0022: \u0022glassfish-admin\u0022, \u0022risk_score\u0022: 35}, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\u065eUn\ufffd\ufffd\ufffd\ufffdx\u0027\ufffd\\nj\\u0011\ufffd\ufffdF\ufffd\ufffdC\ufffd\ufffdG\\u0001F^\ufffd\\u0014\ufffdQ\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\u065eUn\ufffd\ufffd\ufffd\ufffdx\u0027\ufffd\\nj\\u0011\ufffd\ufffdF\ufffd\ufffdC\ufffd\ufffdG\\u0001F^\ufffd\\u0014\ufffdQ\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\u065eUn\ufffd\ufffd\ufffd\ufffdx\u0027\ufffd\\nj\\u0011\ufffd\ufffdF\ufffd\ufffdC\ufffd\ufffdG\\u0001F^\ufffd\\u0014\ufffdQ\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022f6fb99e08d88a19f7523276d8be1bc5256a3be24\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\u065eUn\ufffd\ufffd\ufffd\ufffdx\u0027\ufffd\\nj\\u0011\ufffd\ufffdF\ufffd\ufffdC\ufffd\ufffdG\\u0001F^\ufffd\\u0014\ufffdQ\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022tls_ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022port\u0022: 4848, \u0022service\u0022: \u0022glassfish-admin\u0022, \u0022service_label_fr\u0022: \u0022GLASSFISH ADMIN\u0022}, \u0022evidence_snippet\u0022: \u0022{w\u065eUn\ufffd\ufffd\ufffd\ufffdx\u0027\ufffd\\nj\ufffd\ufffdF\ufffd\ufffdC\ufffd\ufffdGF^\ufffd\ufffdQ\ufffd\ufffd\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\\t\ufffd\ufffd\\n\/5\ufffd\\n4\\n\\r\ufffd\u0022, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via GLASSFISH ADMIN:4848 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00224848 \u00b7 GLASSFISH ADMIN\u0022, \u0022emulator_service\u0022: \u0022glassfish-admin\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 35\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 35, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022glassfish-admin\u0022, \u0022service_label_fr\u0022: \u0022GLASSFISH ADMIN\u0022, \u0022dst_port\u0022: 4848, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0369\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0369\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-glassfish-admin\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\u065eUn\ufffd\ufffd\ufffd\ufffdx\u0027\ufffd\\nj\\u0011\ufffd\ufffdF\ufffd\ufffdC\ufffd\ufffdG\\u0001F^\ufffd\\u0014\ufffdQ\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022tls_ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022port\u0022: 4848, \u0022service\u0022: \u0022glassfish-admin\u0022, \u0022service_label_fr\u0022: \u0022GLASSFISH ADMIN\u0022}, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via GLASSFISH ADMIN:4848 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022{w\u065eUn\ufffd\ufffd\ufffd\ufffdx\u0027\ufffd\\nj\ufffd\ufffdF\ufffd\ufffdC\ufffd\ufffdGF^\ufffd\ufffdQ\ufffd\ufffd\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\\t\ufffd\ufffd\\n\/5\ufffd\\n4\\n\\r\ufffd\u0022, \u0022target_port_label\u0022: \u00224848 \u00b7 GLASSFISH ADMIN\u0022, \u0022emulator_service\u0022: \u0022glassfish-admin\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022meta_truncated\u0022: true, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022glassfish_admin\u0022, \u0022service_banner\u0022: \u0022honeypot-glassfish-admin\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00224848\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022glassfish_emulated\u0022, \u0022net_glassfish_probe\u0022, \u0022tls_clienthello\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022glassfish_emulated\u0022, \u0022net_glassfish_probe\u0022, \u0022tls_clienthello\u0022]","anomalies":"[]","severity":4,"bytes_in":128},{"id":9329182,"ip":"184.105.247.195","ts":"2026-06-16 01:26:07.000000","proto":"tcp","src_port":43982,"dst_port":2083,"service":"cpanel-ssl","classification":"postgres_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a5365727665723a206370737276642f31312e3131300d0a436f6e74656e742d547970653a20746578742f68746d6c0d0a436f6e74656e742d4c656e6774683a2033380d0a0d0a3c68746d6c3e3c626f64793e6350616e656c204c6f67696e3c2f626f64793e3c2f68746d6c3e\u0022, \u0022emulator_response_len\u0022: 125, \u0022bytes_in\u0022: 128, \u0022payload_entropy\u0022: 4.857434561543816, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022cpanel-ssl\u0022, \u0022app_proto\u0022: \u0022cpanel-ssl\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 2083, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00224cc54c7fcd5f1e5ebb94393f5b67f30e90170090\u0022, \u0022event_fingerprint\u0022: \u002280d2812b66b9080b0842670f25ce9d4d3386dae1\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0369\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0369\u0022], \u0022matched_patterns\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022PostgreSQL startup\u0022, \u0022Minecraft varint handshake\u0022, \u0022SOCKS5 greeting\u0022, \u0022SIP TLS ClientHello\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022cpanel-ssl\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00221e77d2996777ef563834bec857eaed16\u0022, \u0022path_pattern_hash\u0022: \u002280f3c71fe26f36a0a9399108643f66c5\u0022, \u0022ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 13, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022}, \u0022tls_ja3_hash\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja3\u0022: \u0022771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0\u0022, \u0022tls_ja4_hash\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_ja4\u0022: \u0022t13d0113_ad3470b4f447_40d2e578a3e2\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 13, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022, \u0022target_context\u0022: {\u0022dst_port\u0022: 2083, \u0022service\u0022: \u0022cpanel-ssl\u0022, \u0022service_name\u0022: \u0022cpanel-ssl\u0022, \u0022risk_score\u0022: 35}, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd0F\ufffd\ufffd\ufffdf!\ufffd\u06b98G\ufffd\u00f9\ufffd\ufffd\ufffd3\u0133\ufffd\\u0004g\ufffdQ\ufffd\\u0012\ufffd\\u0011\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd0F\ufffd\ufffd\ufffdf!\ufffd\u06b98G\ufffd\u00f9\ufffd\ufffd\ufffd3\u0133\ufffd\\u0004g\ufffdQ\ufffd\\u0012\ufffd\\u0011\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd0F\ufffd\ufffd\ufffdf!\ufffd\u06b98G\ufffd\u00f9\ufffd\ufffd\ufffd3\u0133\ufffd\\u0004g\ufffdQ\ufffd\\u0012\ufffd\\u0011\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00227737cf402eff644471806e5c652ebb946e61652d\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd0F\ufffd\ufffd\ufffdf!\ufffd\u06b98G\ufffd\u00f9\ufffd\ufffd\ufffd3\u0133\ufffd\\u0004g\ufffdQ\ufffd\\u0012\ufffd\\u0011\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022tls_ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022port\u0022: 2083, \u0022service\u0022: \u0022cpanel-ssl\u0022, \u0022service_label_fr\u0022: \u0022CPANEL SSL\u0022}, \u0022evidence_snippet\u0022: \u0022{w\ufffd0F\ufffd\ufffd\ufffdf!\ufffd\u06b98G\ufffd\u00f9\ufffd\ufffd\ufffd3\u0133\ufffdg\ufffdQ\ufffd\ufffd\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\\t\ufffd\ufffd\\n\/5\ufffd\\n4\\n\\r\ufffd\u0022, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via CPANEL SSL:2083 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00222083 \u00b7 CPANEL SSL\u0022, \u0022emulator_service\u0022: \u0022cpanel-ssl\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 35\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 35, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022cpanel-ssl\u0022, \u0022service_label_fr\u0022: \u0022CPANEL SSL\u0022, \u0022dst_port\u0022: 2083, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0369\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0369\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-cpanel-ssl\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd0F\ufffd\ufffd\ufffdf!\ufffd\u06b98G\ufffd\u00f9\ufffd\ufffd\ufffd3\u0133\ufffd\\u0004g\ufffdQ\ufffd\\u0012\ufffd\\u0011\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022tls_ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022port\u0022: 2083, \u0022service\u0022: \u0022cpanel-ssl\u0022, \u0022service_label_fr\u0022: \u0022CPANEL SSL\u0022}, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via CPANEL SSL:2083 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022{w\ufffd0F\ufffd\ufffd\ufffdf!\ufffd\u06b98G\ufffd\u00f9\ufffd\ufffd\ufffd3\u0133\ufffdg\ufffdQ\ufffd\ufffd\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\\t\ufffd\ufffd\\n\/5\ufffd\\n4\\n\\r\ufffd\u0022, \u0022target_port_label\u0022: \u00222083 \u00b7 CPANEL SSL\u0022, \u0022emulator_service\u0022: \u0022cpanel-ssl\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022meta_truncated\u0022: true, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022cpanel_ssl\u0022, \u0022service_banner\u0022: \u0022honeypot-cpanel-ssl\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00222083\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022cpanel_ssl_emulated\u0022, \u0022net_cpanel_probe\u0022, \u0022tls_clienthello\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022cpanel_ssl_emulated\u0022, \u0022net_cpanel_probe\u0022, \u0022tls_clienthello\u0022]","anomalies":"[]","severity":3,"bytes_in":128},{"id":9065532,"ip":"184.105.247.195","ts":"2026-06-15 01:22:45.000000","proto":"tcp","src_port":2316,"dst_port":808,"service":"http","classification":"exploit_attempt","waf_score":13,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022]","http_method":"CONNECT","http_target":"www.shadowserver.org:443","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 5, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u00225186dac1dd506c3487aa39a6c8a4a57637399ef6\u0022, \u0022http_host_hash\u0022: \u00226ae3ed4621d9c0dd8cee74f6b1c5b4073913b336\u0022, \u0022http_target_hash\u0022: \u00226b8e04bac019a1bdc3bcbdaa5cdd24320a9a648d\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022CONNECT\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 273, \u0022payload_entropy\u0022: 5.408993570259432, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 808, \u0022risk_waf\u0022: 60.0, \u0022risk_classification\u0022: 72.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 1.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 60.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 41, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022251c350166c67c8f713bcd69ecf886044a0b3c82\u0022, \u0022event_fingerprint\u0022: \u0022e96971d34b4595ff497e3e18dfad1214436858d3\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022confidence\u0022: 0.62, \u0022classification_confidence\u0022: 0.62, \u0022precision_score\u0022: 73, \u0022precision_signals\u0022: [\u0022MITRE-T1190\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1190\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 60.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 41}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 62.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022efff31ee849c981a7783b6add0cf22b7\u0022, \u0022payload_hash\u0022: \u0022aabdf92aa4de33ecfd336cfa20d3b1be\u0022, \u0022path_pattern_hash\u0022: \u0022a0d39411cb42eec21469d044e2155f68\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 808, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 41}, \u0022payload_preview\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) App\u0022, \u0022method\u0022: \u0022CONNECT\u0022, \u0022path\u0022: \u0022www.shadowserver.org:443\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022], \u0022request_line\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\\r\\nConnection: Keep-Alive\\r\\nPragma: no-cache\\r\\nProxy-Connectio\u0022, \u0022payload_snippet\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) App\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022CONNECT\u0022, \u0022path\u0022: \u0022www.shadowserver.org:443\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022], \u0022request_line\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\\r\\nConnection: Keep-Alive\\r\\nPragma: no-cache\\r\\nProxy-Connectio\u0022, \u0022payload_snippet\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) App\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022f9027a79741da52cf349b24f999c37c86efdb18b\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022CONNECT\u0022, \u0022http_path\u0022: \u0022www.shadowserver.org:443\u0022, \u0022request_line\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\u0022, \u0022port\u0022: 808, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) App\u0022, \u0022attack_vector\u0022: \u0022exploit attempt \u00b7 via HTTP:808 \u00b7 (tentative d\u0027exploit) \u00b7 \u2192 www.shadowserver.org:443\u0022, \u0022target_port_label\u0022: \u0022808 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 62 % \u2014 2 tag(s) WAF\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 41\/100 (Moyen) \u2014 MITRE TA0001 \u2014 confiance 62 % \u2014 via HTTP\u0022, \u0022confidence_pct\u0022: 62, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 60.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 41}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 41, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 808, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022MITRE-T1190\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022MITRE-T1190\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022CONNECT\u0022, \u0022http_path\u0022: \u0022www.shadowserver.org:443\u0022, \u0022request_line\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\u0022, \u0022port\u0022: 808, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022exploit attempt \u00b7 via HTTP:808 \u00b7 (tentative d\u0027exploit) \u00b7 \u2192 www.shadowserver.org:443\u0022, \u0022evidence_snippet\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) App\u0022, \u0022target_port_label\u0022: \u0022808 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 62 % \u2014 2 tag(s) WAF\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 62 % \u2014 Score WAF 60 \u00b7 2 tag(s) WAF\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u0022808\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022http_dangerous_method\u0022, \u0022http_method_uncommon\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"www.shadowserver.org","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022http_dangerous_method\u0022, \u0022http_method_uncommon\u0022]","anomalies":"[]","severity":7,"bytes_in":273},{"id":9065527,"ip":"184.105.247.195","ts":"2026-06-15 01:22:43.000000","proto":"tcp","src_port":2312,"dst_port":808,"service":"http","classification":"exploit_attempt","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"http:\/\/api.ipify.org\/?format=json","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 2, \u0022http_query_params\u0022: 1, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u00225186dac1dd506c3487aa39a6c8a4a57637399ef6\u0022, \u0022http_host_hash\u0022: \u0022d29a2ecf00a8df01957221d1f0dff7b5d932ee52\u0022, \u0022http_target_hash\u0022: \u0022c992eafe99bb93048b184fe302c46a2c7c06d83d\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 199, \u0022payload_entropy\u0022: 5.432339101056475, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 808, \u0022risk_waf\u0022: 72.0, \u0022risk_classification\u0022: 72.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 1.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 40, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022e4552a41a2e27801a04e3e418c5c726218871c9c\u0022, \u0022event_fingerprint\u0022: \u00226da997f4e5265c8d3cb10b64e7e12dc3d996c5c9\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 29%\u0022, \u0022confidence\u0022: 0.29, \u0022classification_confidence\u0022: 0.29, \u0022precision_score\u0022: 35, \u0022precision_signals\u0022: [\u0022MITRE-T1190\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1190\u0022], \u0022matched_patterns\u0022: [\u0022pat-0103\u0022], \u0022matched_pattern_names\u0022: [\u0022LFI Double-dot bypass\u0022], \u0022pattern_ids\u0022: [\u0022pat-0103\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 40}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 29.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022efff31ee849c981a7783b6add0cf22b7\u0022, \u0022payload_hash\u0022: \u00221030f989cb9522423f292a24da3e4a68\u0022, \u0022path_pattern_hash\u0022: \u00229e6886b350be931fd969e2abc3b79698\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 808, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 40}, \u0022payload_preview\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) Apple\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022query_string\u0022: \u0022format=json\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) Apple\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022query_string\u0022: \u0022format=json\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) Apple\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 29%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022093f6a4005e7e9caa4b0b4f6c5f9bb35ee132a18\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/\u0022, \u0022request_line\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\u0022, \u0022port\u0022: 808, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) Apple\u0022, \u0022attack_vector\u0022: \u0022exploit attempt \u00b7 via HTTP:808 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u0022808 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 29 % \u2014 3 tag(s) WAF\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 29%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 29%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 40\/100 (Moyen) \u2014 MITRE TA0001 \u2014 confiance 29 % \u2014 via HTTP\u0022, \u0022confidence_pct\u0022: 29, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 40}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 40, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 808, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022MITRE-T1190\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022MITRE-T1190\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/\u0022, \u0022request_line\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\u0022, \u0022port\u0022: 808, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022exploit attempt \u00b7 via HTTP:808 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) Apple\u0022, \u0022target_port_label\u0022: \u0022808 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 29 % \u2014 3 tag(s) WAF\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 29 % \u2014 Score WAF 72 \u00b7 3 tag(s) WAF\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u0022808\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_absolute_uri\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"api.ipify.org","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_absolute_uri\u0022]","anomalies":"[]","severity":8,"bytes_in":199},{"id":9065487,"ip":"184.105.247.195","ts":"2026-06-15 01:22:04.000000","proto":"tcp","src_port":57028,"dst_port":808,"service":"http","classification":"exploit_attempt","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u002262ccd2a15dd05f306fc4db0130eee094d21d9527\u0022, \u0022http_host_hash\u0022: \u00225ff341c6c9fd5ee9340b3a8d5d6696bdd61a3b19\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 209, \u0022payload_entropy\u0022: 5.421491178455289, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 808, \u0022risk_waf\u0022: 72.0, \u0022risk_classification\u0022: 72.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 25.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 1.4, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 25.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c3b62219943f90d28418a565d1abb5e4c1f44e2e\u0022, \u0022event_fingerprint\u0022: \u002252e3c9ccd2494e74559049ebe4c06c78dc91411e\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022confidence\u0022: 0.62, \u0022classification_confidence\u0022: 0.62, \u0022precision_score\u0022: 73, \u0022precision_signals\u0022: [\u0022MITRE-T1190\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1190\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 25.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 62.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022a0925343a20453a4faddd2b11c69b3d7\u0022, \u0022payload_hash\u0022: \u0022e3b2b8a09e968edb436ba47cd26cbf8d\u0022, \u0022path_pattern_hash\u0022: \u00228a5edab282632443219e051e4ade2d1d\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 808, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:808\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit\/537.75.14 (KHTML, l\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit\/537.75.14 (KHTML, like Gecko) Version\/7.0.3 Safari\/7046A194A\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:808\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit\/537.75.14 (KHTML, like Gecko) Version\/7.0.3 Safari\/7046A194A\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:808\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit\/537.75.14 (KHTML, l\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit\/537.75.14 (KHTML, like Gecko) Version\/7.0.3 Safari\/7046A194A\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:808\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit\/537.75.14 (KHTML, like Gecko) Version\/7.0.3 Safari\/7046A194A\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:808\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit\/537.75.14 (KHTML, l\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022dc061d5b1ee9130c3f7a4d14b3e97cb9d30e1478\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/\u0022, \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit\/537.75.14 (KHTML, like Gecko) Version\/7.0.3 Safari\/7046A194A\u0022, \u0022port\u0022: 808, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:808\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit\/537.75.14 (KHTML, l\u0022, \u0022attack_vector\u0022: \u0022exploit attempt \u00b7 via HTTP:808 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u0022808 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 62 % \u2014 3 tag(s) WAF\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 confiance 62 % \u2014 via HTTP\u0022, \u0022confidence_pct\u0022: 62, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 25.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 808, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022MITRE-T1190\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022MITRE-T1190\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/\u0022, \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit\/537.75.14 (KHTML, like Gecko) Version\/7.0.3 Safari\/7046A194A\u0022, \u0022port\u0022: 808, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022exploit attempt \u00b7 via HTTP:808 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:808\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit\/537.75.14 (KHTML, l\u0022, \u0022target_port_label\u0022: \u0022808 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 62 % \u2014 3 tag(s) WAF\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 62 % \u2014 Score WAF 72 \u00b7 3 tag(s) WAF\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u0022808\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:808","http_user_agent":"Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit\/537.75.14 (KHTML, like Gecko) Version\/7.0.3 Safari\/7046A194A","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":209},{"id":9064408,"ip":"184.105.247.195","ts":"2026-06-15 00:59:19.000000","proto":"tcp","src_port":17368,"dst_port":8010,"service":"http-alt-8010","classification":"postgres_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a5365727665723a204170616368652f322e342e35370d0a436f6e74656e742d4c656e6774683a20320d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a4f4b\u0022, \u0022emulator_response_len\u0022: 82, \u0022bytes_in\u0022: 128, \u0022payload_entropy\u0022: 4.780551328502067, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http-alt-8010\u0022, \u0022app_proto\u0022: \u0022http-alt-8010\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 8010, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 30.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002216de40252f09d4e165e9850fd86974e2649b2844\u0022, \u0022event_fingerprint\u0022: \u00223c8bec9ff6243353dd9f4241f81b225f3feb7ea2\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0369\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0369\u0022], \u0022matched_patterns\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022PostgreSQL startup\u0022, \u0022Minecraft varint handshake\u0022, \u0022SOCKS5 greeting\u0022, \u0022SIP TLS ClientHello\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http-alt-8010\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022f2e1ff63ef8e311dd44fd7d899f5ad84\u0022, \u0022path_pattern_hash\u0022: \u002280f3c71fe26f36a0a9399108643f66c5\u0022, \u0022ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 13, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022}, \u0022tls_ja3_hash\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja3\u0022: \u0022771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0\u0022, \u0022tls_ja4_hash\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_ja4\u0022: \u0022t13d0113_ad3470b4f447_40d2e578a3e2\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 13, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022, \u0022target_context\u0022: {\u0022dst_port\u0022: 8010, \u0022service\u0022: \u0022http-alt-8010\u0022, \u0022service_name\u0022: \u0022http-alt-8010\u0022, \u0022risk_score\u0022: 35}, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\\u0001\ufffd\ufffd|\ufffdk\ufffdK\ufffd\\u0010\u04dd\ufffd\/m\ufffd7\\u00040zd\ufffdn@\\u0015*R\u0477\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\\u0001\ufffd\ufffd|\ufffdk\ufffdK\ufffd\\u0010\u04dd\ufffd\/m\ufffd7\\u00040zd\ufffdn@\\u0015*R\u0477\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\\u0001\ufffd\ufffd|\ufffdk\ufffdK\ufffd\\u0010\u04dd\ufffd\/m\ufffd7\\u00040zd\ufffdn@\\u0015*R\u0477\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00224e3f925318b54b19133eb1ed95403d60272a6d19\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\\u0001\ufffd\ufffd|\ufffdk\ufffdK\ufffd\\u0010\u04dd\ufffd\/m\ufffd7\\u00040zd\ufffdn@\\u0015*R\u0477\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022tls_ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022port\u0022: 8010, \u0022service\u0022: \u0022http-alt-8010\u0022, \u0022service_label_fr\u0022: \u0022HTTP ALT 8010\u0022}, \u0022evidence_snippet\u0022: \u0022{w\ufffd\ufffd\ufffd|\ufffdk\ufffdK\ufffd\u04dd\ufffd\/m\ufffd70zd\ufffdn@*R\u0477\ufffd\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\\t\ufffd\ufffd\\n\/5\ufffd\\n4\\n\\r\ufffd\u0022, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via HTTP ALT 8010:8010 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00228010 \u00b7 HTTP ALT 8010\u0022, \u0022emulator_service\u0022: \u0022http-alt-8010\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 35\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 30.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 35, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022http-alt-8010\u0022, \u0022service_label_fr\u0022: \u0022HTTP ALT 8010\u0022, \u0022dst_port\u0022: 8010, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0369\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0369\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http-alt-8010\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\\u0001\ufffd\ufffd|\ufffdk\ufffdK\ufffd\\u0010\u04dd\ufffd\/m\ufffd7\\u00040zd\ufffdn@\\u0015*R\u0477\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022tls_ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022port\u0022: 8010, \u0022service\u0022: \u0022http-alt-8010\u0022, \u0022service_label_fr\u0022: \u0022HTTP ALT 8010\u0022}, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via HTTP ALT 8010:8010 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022{w\ufffd\ufffd\ufffd|\ufffdk\ufffdK\ufffd\u04dd\ufffd\/m\ufffd70zd\ufffdn@*R\u0477\ufffd\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\\t\ufffd\ufffd\\n\/5\ufffd\\n4\\n\\r\ufffd\u0022, \u0022target_port_label\u0022: \u00228010 \u00b7 HTTP ALT 8010\u0022, \u0022emulator_service\u0022: \u0022http-alt-8010\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022meta_truncated\u0022: true, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http_alt_8010\u0022, \u0022service_banner\u0022: \u0022honeypot-http-alt-8010\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228010\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022tls_clienthello\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_clienthello\u0022]","anomalies":"[]","severity":3,"bytes_in":128},{"id":8544493,"ip":"184.105.247.195","ts":"2026-06-08 03:40:24.000000","proto":"tcp","src_port":28046,"dst_port":3128,"service":"http","classification":"exploit_attempt","waf_score":13,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022]","http_method":"CONNECT","http_target":"www.shadowserver.org:443","sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a5365727665723a204170616368652f322e342e35370d0a436f6e74656e742d4c656e6774683a20320d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a4f4b\u0022, \u0022emulator_response_len\u0022: 82, \u0022http_header_count\u0022: 5, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022716324c417916203c790f98e099ae6e192f53242\u0022, \u0022http_host_hash\u0022: \u00226ae3ed4621d9c0dd8cee74f6b1c5b4073913b336\u0022, \u0022http_target_hash\u0022: \u00226b8e04bac019a1bdc3bcbdaa5cdd24320a9a648d\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022CONNECT\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 303, \u0022payload_entropy\u0022: 5.390945278628893, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 3128, \u0022risk_waf\u0022: 60.0, \u0022risk_classification\u0022: 72.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 43.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 6.2, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 60.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002227a86ce54c4f6c6a397a4411704d67d33bc05536\u0022, \u0022event_fingerprint\u0022: \u002271f8fb0e20f6ae6349921424662f2b5e1af3d127\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022confidence\u0022: 0.62, \u0022classification_confidence\u0022: 0.62, \u0022precision_score\u0022: 73, \u0022precision_signals\u0022: [\u0022MITRE-T1190\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1190\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 60.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 45}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 62.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u00221d6b36839b4adf1b86c5d9341d6b52e9\u0022, \u0022payload_hash\u0022: \u0022a4948ffa83fc8631716ae24d97e31df8\u0022, \u0022path_pattern_hash\u0022: \u0022a0d39411cb42eec21469d044e2155f68\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 3128, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) App\u0022, \u0022method\u0022: \u0022CONNECT\u0022, \u0022path\u0022: \u0022www.shadowserver.org:443\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022], \u0022request_line\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36\\r\\nConnection: Keep-Alive\\r\\nPra\u0022, \u0022payload_snippet\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) App\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022CONNECT\u0022, \u0022path\u0022: \u0022www.shadowserver.org:443\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022], \u0022request_line\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36\\r\\nConnection: Keep-Alive\\r\\nPra\u0022, \u0022payload_snippet\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) App\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022d972aa5967b5303b3d79df3010de74ab8eae4865\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022CONNECT\u0022, \u0022http_path\u0022: \u0022www.shadowserver.org:443\u0022, \u0022request_line\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534\u2026\u0022, \u0022port\u0022: 3128, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) App\u0022, \u0022attack_vector\u0022: \u0022exploit attempt \u00b7 via HTTP:3128 \u00b7 (tentative d\u0027exploit) \u00b7 \u2192 www.shadowserver.org:443\u0022, \u0022target_port_label\u0022: \u00223128 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 62 % \u2014 2 tag(s) WAF\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 45\/100 (Moyen) \u2014 MITRE TA0001 \u2014 confiance 62 % \u2014 via HTTP\u0022, \u0022confidence_pct\u0022: 62, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 60.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 3128, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022MITRE-T1190\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022MITRE-T1190\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022CONNECT\u0022, \u0022http_path\u0022: \u0022www.shadowserver.org:443\u0022, \u0022request_line\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534\u2026\u0022, \u0022port\u0022: 3128, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022exploit attempt \u00b7 via HTTP:3128 \u00b7 (tentative d\u0027exploit) \u00b7 \u2192 www.shadowserver.org:443\u0022, \u0022evidence_snippet\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) App\u0022, \u0022target_port_label\u0022: \u00223128 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 62 % \u2014 2 tag(s) WAF\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 62 % \u2014 Score WAF 60 \u00b7 2 tag(s) WAF\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00223128\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022http_dangerous_method\u0022, \u0022http_method_uncommon\u0022, \u0022net_web_probe\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"www.shadowserver.org","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022http_dangerous_method\u0022, \u0022http_method_uncommon\u0022, \u0022net_web_probe\u0022]","anomalies":"[]","severity":7,"bytes_in":303},{"id":8544488,"ip":"184.105.247.195","ts":"2026-06-08 03:40:15.000000","proto":"tcp","src_port":55156,"dst_port":3128,"service":"http","classification":"exploit_attempt","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"http:\/\/api.ipify.org\/?format=json","sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a5365727665723a204170616368652f322e342e35370d0a436f6e74656e742d4c656e6774683a20320d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a4f4b\u0022, \u0022emulator_response_len\u0022: 82, \u0022http_header_count\u0022: 2, \u0022http_query_params\u0022: 1, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022716324c417916203c790f98e099ae6e192f53242\u0022, \u0022http_host_hash\u0022: \u0022d29a2ecf00a8df01957221d1f0dff7b5d932ee52\u0022, \u0022http_target_hash\u0022: \u0022c992eafe99bb93048b184fe302c46a2c7c06d83d\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 229, \u0022payload_entropy\u0022: 5.400622961003493, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 3128, \u0022risk_waf\u0022: 72.0, \u0022risk_classification\u0022: 72.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 43.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 6.2, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00227d590a9f494a631bc96f351057bff942d6dcb26e\u0022, \u0022event_fingerprint\u0022: \u0022c29206d9b0a058f69acd8a10da1bf3d37554cd3b\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 29%\u0022, \u0022confidence\u0022: 0.29, \u0022classification_confidence\u0022: 0.29, \u0022precision_score\u0022: 35, \u0022precision_signals\u0022: [\u0022MITRE-T1190\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1190\u0022], \u0022matched_patterns\u0022: [\u0022pat-0103\u0022], \u0022matched_pattern_names\u0022: [\u0022LFI Double-dot bypass\u0022], \u0022pattern_ids\u0022: [\u0022pat-0103\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 45}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 29.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u00221d6b36839b4adf1b86c5d9341d6b52e9\u0022, \u0022payload_hash\u0022: \u00225edfba362270317f64a8f0ac4e7b3310\u0022, \u0022path_pattern_hash\u0022: \u00229e6886b350be931fd969e2abc3b79698\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 3128, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) Apple\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022query_string\u0022: \u0022format=json\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) Apple\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022query_string\u0022: \u0022format=json\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) Apple\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 29%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002205dd303bb5393f880e8e8055bf346ff5a59e357b\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/\u0022, \u0022request_line\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534\u2026\u0022, \u0022port\u0022: 3128, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) Apple\u0022, \u0022attack_vector\u0022: \u0022exploit attempt \u00b7 via HTTP:3128 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00223128 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 29 % \u2014 3 tag(s) WAF\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 29%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 29%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 45\/100 (Moyen) \u2014 MITRE TA0001 \u2014 confiance 29 % \u2014 via HTTP\u0022, \u0022confidence_pct\u0022: 29, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 3128, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022MITRE-T1190\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022MITRE-T1190\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/\u0022, \u0022request_line\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534\u2026\u0022, \u0022port\u0022: 3128, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022exploit attempt \u00b7 via HTTP:3128 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) Apple\u0022, \u0022target_port_label\u0022: \u00223128 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 29 % \u2014 3 tag(s) WAF\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 29 % \u2014 Score WAF 72 \u00b7 3 tag(s) WAF\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00223128\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_absolute_uri\u0022, \u0022net_web_probe\u0022], \u0022behavior_alert_count\u0022: 1, \u0022behavior_priority\u0022: 96}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"api.ipify.org","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_absolute_uri\u0022, \u0022net_web_probe\u0022]","anomalies":"[]","severity":8,"bytes_in":229},{"id":8544480,"ip":"184.105.247.195","ts":"2026-06-08 03:40:02.000000","proto":"tcp","src_port":23804,"dst_port":3128,"service":"http","classification":"web_probe","waf_score":13,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022]","http_method":"GET","http_target":"\/favicon.ico","sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a5365727665723a206e67696e782f312e32342e300d0a436f6e74656e742d547970653a20696d6167652f782d69636f6e0d0a436f6e74656e742d4c656e6774683a2032320d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a0000010001001010000001002000680400001600\u0022, \u0022emulator_response_len\u0022: 130, \u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: \u0022ico\u0022, \u0022http_ua_hash\u0022: \u0022716324c417916203c790f98e099ae6e192f53242\u0022, \u0022http_host_hash\u0022: \u00220004f205c8c9eec39df22e7d5c19060a1bc84a1b\u0022, \u0022http_target_hash\u0022: \u0022a40fba6620dee3abd15532f18848dacb6bb80f01\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 246, \u0022payload_entropy\u0022: 5.419499262443658, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 3128, \u0022risk_waf\u0022: 60.0, \u0022risk_classification\u0022: 42.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 33.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 5.5, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 60.0, \u0022classification\u0022: 42.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 33.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 42, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022e49d945b3830fba172c47726df7e61fb743342eb\u0022, \u0022event_fingerprint\u0022: \u002202bc564c938159860779bd41a0d67dfc0ad90d5e\u0022, \u0022classification_reason\u0022: \u0022Sonde HTTP (tag rce-0) \u00b7 confiance 50%\u0022, \u0022confidence\u0022: 0.5, \u0022classification_confidence\u0022: 0.5, \u0022precision_score\u0022: 94, \u0022precision_signals\u0022: [\u0022INT-benign-favicon\u0022, \u0022INT-single-port\u0022, \u0022INT-benign-path-cap\u0022], \u0022kb_rule_ids\u0022: [\u0022INT-benign-favicon\u0022, \u0022INT-single-port\u0022, \u0022INT-benign-path-cap\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 60.0, \u0022classification\u0022: 42.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 33.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 42}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u00221d6b36839b4adf1b86c5d9341d6b52e9\u0022, \u0022payload_hash\u0022: \u0022d01322be0c720d21ba8cc22a58d3e1b8\u0022, \u0022path_pattern_hash\u0022: \u0022b18036488649e7cc8a55b0a02c8b737a\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 3128, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 42}, \u0022payload_preview\u0022: \u0022GET \/favicon.ico HTTP\/1.1\\r\\nHost: 62.3.50.33:3128\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTM\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/favicon.ico\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022], \u0022request_line\u0022: \u0022GET \/favicon.ico HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/favicon.ico HTTP\/1.1\\r\\nHost: 62.3.50.33:3128\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/favicon.ico HTTP\/1.1\\r\\nHost: 62.3.50.33:3128\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTM\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/favicon.ico\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022], \u0022request_line\u0022: \u0022GET \/favicon.ico HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/favicon.ico HTTP\/1.1\\r\\nHost: 62.3.50.33:3128\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/favicon.ico HTTP\/1.1\\r\\nHost: 62.3.50.33:3128\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTM\u0022, \u0022classification_reason\u0022: \u0022Sonde HTTP (tag rce-0) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022a7d8d8bebefbd4269b58869813a42c8436bd56a3\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/favicon.ico\u0022, \u0022request_line\u0022: \u0022GET \/favicon.ico HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534\u2026\u0022, \u0022port\u0022: 3128, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/favicon.ico HTTP\/1.1\\r\\nHost: 62.3.50.33:3128\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTM\u0022, \u0022attack_vector\u0022: \u0022Sonde HTTP \u00b7 via HTTP:3128 \u00b7 (sonde \/ probe) \u00b7 \u2192 \/favicon.ico\u0022, \u0022target_port_label\u0022: \u00223128 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9 \u00b7 2 tag(s) WAF\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Sonde HTTP (tag rce-0) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Sonde HTTP (tag rce-0) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 42\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 60.0, \u0022classification\u0022: 42.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 33.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 42}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 42, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 3128, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022INT-benign-favicon\u0022, \u0022INT-single-port\u0022, \u0022INT-benign-path-cap\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022Requ\u00eate favicon.ico\u0022, \u0022Single Port\u0022, \u0022Chemin b\u00e9nin connu\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/favicon.ico\u0022, \u0022request_line\u0022: \u0022GET \/favicon.ico HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534\u2026\u0022, \u0022port\u0022: 3128, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022Sonde HTTP \u00b7 via HTTP:3128 \u00b7 (sonde \/ probe) \u00b7 \u2192 \/favicon.ico\u0022, \u0022evidence_snippet\u0022: \u0022GET \/favicon.ico HTTP\/1.1\\r\\nHost: 62.3.50.33:3128\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTM\u0022, \u0022target_port_label\u0022: \u00223128 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9 \u00b7 2 tag(s) WAF\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 60 \u00b7 2 tag(s) WAF\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00223128\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022net_web_probe\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3128","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 YaBrowser\/23.7.0.2534 Yowser\/2.5 Safari\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022net_web_probe\u0022]","anomalies":"[]","severity":7,"bytes_in":246},{"id":8544466,"ip":"184.105.247.195","ts":"2026-06-08 03:39:40.000000","proto":"tcp","src_port":45314,"dst_port":3128,"service":"http","classification":"exploit_attempt","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a5365727665723a204170616368652f322e342e35370d0a436f6e74656e742d4c656e6774683a20320d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a4f4b\u0022, \u0022emulator_response_len\u0022: 82, \u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022fb99546d153e45c3c498353b7103de2866a4cc10\u0022, \u0022http_host_hash\u0022: \u00220004f205c8c9eec39df22e7d5c19060a1bc84a1b\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 216, \u0022payload_entropy\u0022: 5.409143360339413, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 3128, \u0022risk_waf\u0022: 72.0, \u0022risk_classification\u0022: 72.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 33.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 5.9, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 33.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 48, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022fd26819072250dcb8b4055072de225d2cf030e2f\u0022, \u0022event_fingerprint\u0022: \u0022b44d6a5705c872a60d428b36f768df94eca10fde\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022confidence\u0022: 0.62, \u0022classification_confidence\u0022: 0.62, \u0022precision_score\u0022: 73, \u0022precision_signals\u0022: [\u0022MITRE-T1190\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1190\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 33.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 48}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 62.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022dd169ad94998d35e3c6ff3cc9ced8a16\u0022, \u0022payload_hash\u0022: \u00228a93d4e9ccd84797b9d15b7b6f45e21d\u0022, \u0022path_pattern_hash\u0022: \u00228a5edab282632443219e051e4ade2d1d\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 3128, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 48}, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:3128\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/122.0.0.0 Safari\/537.36 OPR\/108.0.0.0\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:3128\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/122.0.0.0 Safari\/537.36 OPR\/108.0.0.0\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:3128\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/122.0.0.0 Safari\/537.36 OPR\/108.0.0.0\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:3128\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/122.0.0.0 Safari\/537.36 OPR\/108.0.0.0\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:3128\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00225977c2e91f86680861ccce0698b7918ed4389416\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/\u0022, \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/122.0.0.0 Safari\/537.36 OPR\/108\u2026\u0022, \u0022port\u0022: 3128, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:3128\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022attack_vector\u0022: \u0022exploit attempt \u00b7 via HTTP:3128 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00223128 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 62 % \u2014 3 tag(s) WAF\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 48\/100 (Moyen) \u2014 MITRE TA0001 \u2014 confiance 62 % \u2014 via HTTP\u0022, \u0022confidence_pct\u0022: 62, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 33.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 48}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 48, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 3128, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022MITRE-T1190\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022MITRE-T1190\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/\u0022, \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/122.0.0.0 Safari\/537.36 OPR\/108\u2026\u0022, \u0022port\u0022: 3128, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022exploit attempt \u00b7 via HTTP:3128 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:3128\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gec\u0022, \u0022target_port_label\u0022: \u00223128 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 62 % \u2014 3 tag(s) WAF\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 62 % \u2014 Score WAF 72 \u00b7 3 tag(s) WAF\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00223128\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022net_web_probe\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3128","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/122.0.0.0 Safari\/537.36 OPR\/108.0.0.0","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022net_web_probe\u0022]","anomalies":"[]","severity":8,"bytes_in":216},{"id":8534689,"ip":"184.105.247.195","ts":"2026-06-08 01:11:55.000000","proto":"tcp","src_port":39020,"dst_port":444,"service":"tls","classification":"postgres_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u002235fa0a83e466acbec1cfbb9016d550ab\u0022, \u0022tls_sni\u0022: null, \u0022tls_weak_cipher\u0022: true, \u0022tls_weak_cipher_count\u0022: 4, \u0022bytes_in\u0022: 243, \u0022payload_entropy\u0022: 5.893881048680874, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 444, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 43.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 6, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00229bff362b5e4b1fc54e3e921cb3112e46219b6d26\u0022, \u0022event_fingerprint\u0022: \u002270b05747c4e545e62e214ddf8300170578c21fcb\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0369\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0369\u0022], \u0022matched_patterns\u0022: [\u0022pat-0369\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022PostgreSQL startup\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022SOCKS5 greeting\u0022, \u0022SIP TLS ClientHello\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0369\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022tls\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022ja3\u0022: \u002235fa0a83e466acbec1cfbb9016d550ab\u0022, \u0022payload_hash\u0022: \u00224884f0eb8b0e51901bc5c8fe04ae1033\u0022, \u0022path_pattern_hash\u0022: \u002280f3c71fe26f36a0a9399108643f66c5\u0022, \u0022ja4\u0022: \u00227b5e3a15097abc10f88e98257ea51010\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 19, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022}, \u0022tls_ja3\u0022: \u0022771,52392-52393-49199-49200-49195-49196-49171-49161-49172-49162-156-157-47-53-49170-10-4867-4865-4866,5-10-11-13-65281-18-43-51,29-23-24-25,0\u0022, \u0022tls_ja4_hash\u0022: \u00227b5e3a15097abc10f88e98257ea51010\u0022, \u0022tls_ja4\u0022: \u0022t13d0119_86cb3216d275_cc710080a5f9\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 19, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022, \u0022target_context\u0022: {\u0022dst_port\u0022: 444, \u0022service\u0022: \u0022tls\u0022, \u0022service_name\u0022: \u0022tls\u0022, \u0022risk_score\u0022: 35}, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003\ufffd\\u001aOa\ufffdk\ufffd\u0027N\ufffdwH\ufffd9Rm\ufffd\ufffdI\ufffd\ufffd\\u0004\ufffd\\u001a\ufffd\ufffd\ufffd9#QW \\u0012s\ufffd\ufffd\ufffd\\u0001\ufffd\\u001f\ufffd\\u0003\ufffd\ufffd\\u000bi\ufffd\ufffdK\ufffd\ufffd\\u000eF\ufffd\\u0001p\ufffdSC\ufffd\ufffd\u073e\\u0000\u0026\u0328\u0329\ufffd\/\ufffd0\ufffd+\ufffd,\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\ufffd\\u0000\ufffd\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0013\\u0003\\u0013\\u0001\\u0013\\u0002\\u0001\\u0000\\u0000{\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003\ufffd\\u001aOa\ufffdk\ufffd\u0027N\ufffdwH\ufffd9Rm\ufffd\ufffdI\ufffd\ufffd\\u0004\ufffd\\u001a\ufffd\ufffd\ufffd9#QW \\u0012s\ufffd\ufffd\ufffd\\u0001\ufffd\\u001f\ufffd\\u0003\ufffd\ufffd\\u000bi\ufffd\ufffdK\ufffd\ufffd\\u000eF\ufffd\\u0001p\ufffdSC\ufffd\ufffd\u073e\\u0000\u0026\u0328\u0329\ufffd\/\ufffd0\ufffd+\ufffd,\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\ufffd\\u0000\ufffd\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0013\\u0003\\u0013\\u0001\\u0013\\u0002\\u0001\\u0000\\u0000{\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\n\\u0000\\b\\u0000\\u001d\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u001a\\u0000\\u0018\\b\\u0004\\u0004\\u0003\\b\\u0007\\b\\u0005\\b\\u0006\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\\u0005\\u0003\\u0006\\u0003\\u0002\\u0001\\u0002\\u0003\ufffd\\u0001\\u0000\\u0001\\u0000\\u0000\\u0012\\u0000\\u0000\\u0000+\\u0000\\t\\b\\u0003\\u0004\\u0003\\u0003\\u0003\\u0002\\u0003\\u0001\\u00003\\u0000\u0026\\u0000$\\u0000\\u001d\\u0000 ?V\ufffd\ufffdf\ufffdL\u003E\\u001c\ud8c2\udca0@\ufffdT\ufffd!I\ufffd\ufffd\\u0010n\\u0006\\u001e\ufffd\ufffd\ufffd\ufffd\ufffd4\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003\ufffd\\u001aOa\ufffdk\ufffd\u0027N\ufffdwH\ufffd9Rm\ufffd\ufffdI\ufffd\ufffd\\u0004\ufffd\\u001a\ufffd\ufffd\ufffd9#QW \\u0012s\ufffd\ufffd\ufffd\\u0001\ufffd\\u001f\ufffd\\u0003\ufffd\ufffd\\u000bi\ufffd\ufffdK\ufffd\ufffd\\u000eF\ufffd\\u0001p\ufffdSC\ufffd\ufffd\u073e\\u0000\u0026\u0328\u0329\ufffd\/\ufffd0\ufffd+\ufffd,\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\ufffd\\u0000\ufffd\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0013\\u0003\\u0013\\u0001\\u0013\\u0002\\u0001\\u0000\\u0000{\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002255c7ce0bdf7ab4f97e1bb8c21a0c1e7de99d58f7\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003\ufffd\\u001aOa\ufffdk\ufffd\u0027N\ufffdwH\ufffd9Rm\ufffd\ufffdI\ufffd\ufffd\\u0004\ufffd\\u001a\ufffd\ufffd\ufffd9#QW \\u0012s\ufffd\ufffd\ufffd\\u0001\ufffd\\u001f\ufffd\\u0003\ufffd\ufffd\\u000bi\ufffd\ufffdK\ufffd\ufffd\\u000eF\ufffd\\u0001p\ufffdSC\ufffd\ufffd\u073e\\u0000\u0026\u0328\u0329\ufffd\/\ufffd0\ufffd+\ufffd,\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\ufffd\\u0000\ufffd\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0013\\u0003\\u0013\\u0001\\u0013\\u0002\\u0001\\u0000\\u0000{\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\u0022, \u0022tls_ja3\u0022: \u002235fa0a83e466acbec1cfbb9016d550ab\u0022, \u0022tls_ja4\u0022: \u00227b5e3a15097abc10f88e98257ea51010\u0022, \u0022port\u0022: 444, \u0022service\u0022: \u0022tls\u0022, \u0022service_label_fr\u0022: \u0022TLS\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffd\ufffdOa\ufffdk\ufffd\u0027N\ufffdwH\ufffd9Rm\ufffd\ufffdI\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd9#QW s\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdi\ufffd\ufffdK\ufffd\ufffdF\ufffdp\ufffdSC\ufffd\ufffd\u073e\u0026\u0328\u0329\ufffd\/\ufffd0\ufffd+\ufffd,\ufffd\ufffd\\t\ufffd\ufffd\\n\ufffd\ufffd\/5\ufffd\\n{\u0022, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via TLS:444 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u0022444 \u00b7 TLS\u0022, \u0022emulator_service\u0022: \u0022tls\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 35\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 35, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022tls\u0022, \u0022service_label_fr\u0022: \u0022TLS\u0022, \u0022dst_port\u0022: 444, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022pat-0369\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0369\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-tls\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003\ufffd\\u001aOa\ufffdk\ufffd\u0027N\ufffdwH\ufffd9Rm\ufffd\ufffdI\ufffd\ufffd\\u0004\ufffd\\u001a\ufffd\ufffd\ufffd9#QW \\u0012s\ufffd\ufffd\ufffd\\u0001\ufffd\\u001f\ufffd\\u0003\ufffd\ufffd\\u000bi\ufffd\ufffdK\ufffd\ufffd\\u000eF\ufffd\\u0001p\ufffdSC\ufffd\ufffd\u073e\\u0000\u0026\u0328\u0329\ufffd\/\ufffd0\ufffd+\ufffd,\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\ufffd\\u0000\ufffd\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0013\\u0003\\u0013\\u0001\\u0013\\u0002\\u0001\\u0000\\u0000{\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\u0022, \u0022tls_ja3\u0022: \u002235fa0a83e466acbec1cfbb9016d550ab\u0022, \u0022tls_ja4\u0022: \u00227b5e3a15097abc10f88e98257ea51010\u0022, \u0022port\u0022: 444, \u0022service\u0022: \u0022tls\u0022, \u0022service_label_fr\u0022: \u0022TLS\u0022}, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via TLS:444 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffd\ufffdOa\ufffdk\ufffd\u0027N\ufffdwH\ufffd9Rm\ufffd\ufffdI\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd9#QW s\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdi\ufffd\ufffdK\ufffd\ufffdF\ufffdp\ufffdSC\ufffd\ufffd\u073e\u0026\u0328\u0329\ufffd\/\ufffd0\ufffd+\ufffd,\ufffd\ufffd\\t\ufffd\ufffd\\n\ufffd\ufffd\/5\ufffd\\n{\u0022, \u0022target_port_label\u0022: \u0022444 \u00b7 TLS\u0022, \u0022emulator_service\u0022: \u0022tls\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022meta_truncated\u0022: true, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022tls\u0022, \u0022service_banner\u0022: \u0022honeypot-tls\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u0022444\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022], \u0022behavior_alert_count\u0022: 1, \u0022behavior_priority\u0022: 72}","tls_sni":null,"tls_ja3_hash":"35fa0a83e466acbec1cfbb9016d550ab","tls_ja3":"771,52392-52393-49199-49200-49195-49196-49171-49161-49172-49162-156-157-47-53-49170-10-4867-4865-4866,5-10-11-13-65281-18-43-51,29-23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022]","anomalies":"[]","severity":4,"bytes_in":243},{"id":8534674,"ip":"184.105.247.195","ts":"2026-06-08 01:11:45.000000","proto":"tcp","src_port":5310,"dst_port":444,"service":"tls","classification":"postgres_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_sni\u0022: null, \u0022tls_weak_cipher\u0022: true, \u0022tls_weak_cipher_count\u0022: 6, \u0022bytes_in\u0022: 128, \u0022payload_entropy\u0022: 4.757006803947931, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 444, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 43.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 6, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00229bff362b5e4b1fc54e3e921cb3112e46219b6d26\u0022, \u0022event_fingerprint\u0022: \u00228b40a48bc548893c3713866ab0b49b15cee7f8a7\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0369\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0369\u0022], \u0022matched_patterns\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022PostgreSQL startup\u0022, \u0022Minecraft varint handshake\u0022, \u0022SOCKS5 greeting\u0022, \u0022SIP TLS ClientHello\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022tls\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022payload_hash\u0022: \u0022ca2eef3dde1c59aa841b8886ac846b89\u0022, \u0022path_pattern_hash\u0022: \u002280f3c71fe26f36a0a9399108643f66c5\u0022, \u0022ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 13, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022}, \u0022tls_ja3\u0022: \u0022771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0\u0022, \u0022tls_ja4_hash\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_ja4\u0022: \u0022t13d0113_ad3470b4f447_40d2e578a3e2\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 13, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022, \u0022target_context\u0022: {\u0022dst_port\u0022: 444, \u0022service\u0022: \u0022tls\u0022, \u0022service_name\u0022: \u0022tls\u0022, \u0022risk_score\u0022: 35}, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\\u0003\ufffdPj\ufffd)\\\u0022P\u003C\\\\\\u001aOR\ufffd\ufffd\ufffd%f\ufffd\ufffd2n~^\\u0006R\ufffdR\ufffd+\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\\u0003\ufffdPj\ufffd)\\\u0022P\u003C\\\\\\u001aOR\ufffd\ufffd\ufffd%f\ufffd\ufffd2n~^\\u0006R\ufffdR\ufffd+\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\\u0003\ufffdPj\ufffd)\\\u0022P\u003C\\\\\\u001aOR\ufffd\ufffd\ufffd%f\ufffd\ufffd2n~^\\u0006R\ufffdR\ufffd+\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00225b0ba06cb2f38508048617f52997dc1af9436c22\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\\u0003\ufffdPj\ufffd)\\\u0022P\u003C\\\\\\u001aOR\ufffd\ufffd\ufffd%f\ufffd\ufffd2n~^\\u0006R\ufffdR\ufffd+\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022tls_ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022port\u0022: 444, \u0022service\u0022: \u0022tls\u0022, \u0022service_label_fr\u0022: \u0022TLS\u0022}, \u0022evidence_snippet\u0022: \u0022{w\ufffdPj\ufffd)\\\u0022P\u003C\\\\OR\ufffd\ufffd\ufffd%f\ufffd\ufffd2n~^R\ufffdR\ufffd+\ufffd\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\\t\ufffd\ufffd\\n\/5\ufffd\\n4\\n\\r\ufffd\u0022, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via TLS:444 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u0022444 \u00b7 TLS\u0022, \u0022emulator_service\u0022: \u0022tls\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 35\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 35, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022tls\u0022, \u0022service_label_fr\u0022: \u0022TLS\u0022, \u0022dst_port\u0022: 444, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022pat-0369\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0369\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-tls\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\\u0003\ufffdPj\ufffd)\\\u0022P\u003C\\\\\\u001aOR\ufffd\ufffd\ufffd%f\ufffd\ufffd2n~^\\u0006R\ufffdR\ufffd+\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022tls_ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022port\u0022: 444, \u0022service\u0022: \u0022tls\u0022, \u0022service_label_fr\u0022: \u0022TLS\u0022}, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via TLS:444 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022{w\ufffdPj\ufffd)\\\u0022P\u003C\\\\OR\ufffd\ufffd\ufffd%f\ufffd\ufffd2n~^R\ufffdR\ufffd+\ufffd\ufffd\/\ufffd+\ufffd\ufffd\ufffd\ufffd\\t\ufffd\ufffd\\n\/5\ufffd\\n4\\n\\r\ufffd\u0022, \u0022target_port_label\u0022: \u0022444 \u00b7 TLS\u0022, \u0022emulator_service\u0022: \u0022tls\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022tls\u0022, \u0022service_banner\u0022: \u0022honeypot-tls\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u0022444\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022]}","tls_sni":null,"tls_ja3_hash":"cba7f34191ef2379c1325641f6c6c4f4","tls_ja3":"771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022]","anomalies":"[]","severity":4,"bytes_in":128},{"id":8500713,"ip":"184.105.247.195","ts":"2026-06-07 13:16:06.000000","proto":"tcp","src_port":14026,"dst_port":2101,"service":"http","classification":"web_probe","waf_score":3,"waf_tags":"[\u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 3, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u00220bae62ac14bbe59ee26262f16729028baddf0654\u0022, \u0022http_host_hash\u0022: null, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 73, \u0022payload_entropy\u0022: 4.714170114867805, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 2101, \u0022risk_waf\u0022: 20.0, \u0022risk_classification\u0022: 38.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.5, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 20.0, \u0022classification\u0022: 38.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022aa8d6972bd0b406f2c29e798d5b4196274e37325\u0022, \u0022event_fingerprint\u0022: \u002255d938b1377cbc0df3239afdabb39b3f6f262b5f\u0022, \u0022classification_reason\u0022: \u0022Sonde HTTP (tag sap-sapcontrol-path) \u00b7 confiance 34%\u0022, \u0022confidence\u0022: 0.34, \u0022classification_confidence\u0022: 0.34, \u0022precision_score\u0022: 40, \u0022precision_signals\u0022: [\u0022INT-single-port\u0022], \u0022kb_rule_ids\u0022: [\u0022INT-single-port\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 20.0, \u0022classification\u0022: 38.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 34.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022604295db1e2a9963906c06cd07756d0b\u0022, \u0022payload_hash\u0022: \u00222c4dbfb8ceed3a2789cbcc08985d00ef\u0022, \u0022path_pattern_hash\u0022: \u00228a5edab282632443219e051e4ade2d1d\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 2101, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 38}, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nUser-Agent: NTRIP\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022user_agent\u0022: \u0022NTRIP\u0022, \u0022waf_tags\u0022: [\u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nUser-Agent: NTRIP\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nUser-Agent: NTRIP\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022user_agent\u0022: \u0022NTRIP\u0022, \u0022waf_tags\u0022: [\u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nUser-Agent: NTRIP\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nUser-Agent: NTRIP\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\u0022, \u0022classification_reason\u0022: \u0022Sonde HTTP (tag sap-sapcontrol-path) \u00b7 confiance 34%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022405541bf43c6bb510245f8735fa4cc8677924852\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Sonde HTTP (tag sap-sapcontrol-path) \u00b7 confiance 34%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Sonde HTTP (tag sap-sapcontrol-path) \u00b7 confiance 34%\u0022, \u0022confidence_pct\u0022: 34, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 20.0, \u0022classification\u0022: 38.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 2101, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022INT-single-port\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022Single Port\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00222101\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950734:sap-sapcontrol-path\u0022, \u0022http_missing_host\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":null,"http_user_agent":"NTRIP","http_referer":null,"tags":"[\u0022950734:sap-sapcontrol-path\u0022, \u0022http_missing_host\u0022]","anomalies":"[]","severity":4,"bytes_in":73},{"id":8438433,"ip":"184.105.247.195","ts":"2026-06-07 04:47:40.000000","proto":"tcp","src_port":5836,"dst_port":8530,"service":"http","classification":"exploit_attempt","waf_score":19,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950470:nosqli-3\u0022]","http_method":"HEAD","http_target":"\/selfupdate\/wuident.cab","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 3, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: \u0022cab\u0022, \u0022http_ua_hash\u0022: \u00226befef60a2383c468a0dc43eb9fa222cafd7a552\u0022, \u0022http_host_hash\u0022: \u0022e9dd49087659f7e6993ea9e8d2ec3c8069a34c38\u0022, \u0022http_target_hash\u0022: \u0022c884719fb6cd5abd125363450bffbb8e666e4b08\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022HEAD\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 161, \u0022payload_entropy\u0022: 5.341717535201049, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 8530, \u0022risk_waf\u0022: 84.0, \u0022risk_classification\u0022: 72.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 25.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 1.8, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 84.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 25.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 48, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022b409a5591dae735cccd4d32840d2cabe220ceea0\u0022, \u0022event_fingerprint\u0022: \u00220e2f62f25ceb6d715d2a8fede2d3425d9193caaa\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022confidence\u0022: 0.62, \u0022classification_confidence\u0022: 0.62, \u0022precision_score\u0022: 73, \u0022precision_signals\u0022: [\u0022MITRE-T1190\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1190\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 84.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 25.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 48}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 62.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022e240edd2834ba03478a6e5f464f91aab\u0022, \u0022payload_hash\u0022: \u0022359a9623eb22771ed96e20903473b12c\u0022, \u0022path_pattern_hash\u0022: \u00222554a2eb643a4eb356521c96692ffd82\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8530, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 48}, \u0022payload_preview\u0022: \u0022HEAD \/selfupdate\/wuident.cab HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/201001\u0022, \u0022method\u0022: \u0022HEAD\u0022, \u0022path\u0022: \u0022\/selfupdate\/wuident.cab\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950470:nosqli-3\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022], \u0022request_line\u0022: \u0022HEAD \/selfupdate\/wuident.cab HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022HEAD \/selfupdate\/wuident.cab HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\\r\\nAccept: *\/*\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022HEAD \/selfupdate\/wuident.cab HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/201001\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022HEAD\u0022, \u0022path\u0022: \u0022\/selfupdate\/wuident.cab\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950470:nosqli-3\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022], \u0022request_line\u0022: \u0022HEAD \/selfupdate\/wuident.cab HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022HEAD \/selfupdate\/wuident.cab HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\\r\\nAccept: *\/*\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022HEAD \/selfupdate\/wuident.cab HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/201001\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00225bb1255c7aa3b4818f0c9fed75a54542ae375187\u0022, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228530\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploit_attempt\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950470:nosqli-3\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8530","http_user_agent":"Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950470:nosqli-3\u0022]","anomalies":"[]","severity":9,"bytes_in":161},{"id":8438411,"ip":"184.105.247.195","ts":"2026-06-07 04:47:17.000000","proto":"tcp","src_port":56362,"dst_port":8530,"service":"http","classification":"exploit_attempt","waf_score":19,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950470:nosqli-3\u0022]","http_method":"GET","http_target":"\/ClientWebService\/Client.asmx?wsdl","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 1, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: \u0022asmx\u0022, \u0022http_ua_hash\u0022: \u00226befef60a2383c468a0dc43eb9fa222cafd7a552\u0022, \u0022http_host_hash\u0022: \u0022e9dd49087659f7e6993ea9e8d2ec3c8069a34c38\u0022, \u0022http_target_hash\u0022: \u0022dcf09aaa1bbf2c3c452c26cc320522c0c9433a06\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 194, \u0022payload_entropy\u0022: 5.416988691495965, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 8530, \u0022risk_waf\u0022: 84.0, \u0022risk_classification\u0022: 72.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 25.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 1.8, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 84.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 25.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 48, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022b409a5591dae735cccd4d32840d2cabe220ceea0\u0022, \u0022event_fingerprint\u0022: \u0022e84c4d98d5aac324e4afbececfd32b814cff0d96\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022confidence\u0022: 0.62, \u0022classification_confidence\u0022: 0.62, \u0022precision_score\u0022: 73, \u0022precision_signals\u0022: [\u0022MITRE-T1190\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1190\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 84.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 25.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 48}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 62.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022e240edd2834ba03478a6e5f464f91aab\u0022, \u0022payload_hash\u0022: \u00221aa910f1436abf421f32acdc6d221a04\u0022, \u0022path_pattern_hash\u0022: \u00228cbf255964d0000c040337a66d8630e9\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8530, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 48}, \u0022payload_preview\u0022: \u0022GET \/ClientWebService\/Client.asmx?wsdl HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Ge\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/ClientWebService\/Client.asmx\u0022, \u0022query_string\u0022: \u0022wsdl\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950470:nosqli-3\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022], \u0022request_line\u0022: \u0022GET \/ClientWebService\/Client.asmx?wsdl HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ClientWebService\/Client.asmx?wsdl HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ClientWebService\/Client.asmx?wsdl HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Ge\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/ClientWebService\/Client.asmx\u0022, \u0022query_string\u0022: \u0022wsdl\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950470:nosqli-3\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022], \u0022request_line\u0022: \u0022GET \/ClientWebService\/Client.asmx?wsdl HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ClientWebService\/Client.asmx?wsdl HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ClientWebService\/Client.asmx?wsdl HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Ge\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022a36956522530bffa0b9e37518ed6d919521ab79e\u0022, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228530\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploit_attempt\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950470:nosqli-3\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8530","http_user_agent":"Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950470:nosqli-3\u0022]","anomalies":"[]","severity":9,"bytes_in":194},{"id":8438345,"ip":"184.105.247.195","ts":"2026-06-07 04:46:15.000000","proto":"tcp","src_port":43934,"dst_port":8530,"service":"http","classification":"exploit_attempt","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u00226befef60a2383c468a0dc43eb9fa222cafd7a552\u0022, \u0022http_host_hash\u0022: \u0022e9dd49087659f7e6993ea9e8d2ec3c8069a34c38\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 161, \u0022payload_entropy\u0022: 5.276248536603278, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 8530, \u0022risk_waf\u0022: 72.0, \u0022risk_classification\u0022: 72.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 25.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 1.8, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 25.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 44, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022f7e64a28974a08516bfeb7c612ab13c614e06be2\u0022, \u0022event_fingerprint\u0022: \u0022ccee1453018b10e3cfd44e6696ad33a7a4835d4d\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022confidence\u0022: 0.62, \u0022classification_confidence\u0022: 0.62, \u0022precision_score\u0022: 73, \u0022precision_signals\u0022: [\u0022MITRE-T1190\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1190\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 25.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 44}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 62.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022e240edd2834ba03478a6e5f464f91aab\u0022, \u0022payload_hash\u0022: \u002293258a14b61d9a3768799e8b5dd53437\u0022, \u0022path_pattern_hash\u0022: \u00228a5edab282632443219e051e4ade2d1d\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8530, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 44}, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\\r\\nAccep\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\\r\\nAccep\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:8530\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0\\r\\nAccep\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002217f5530089140b11ca22bc29b58f4bb2657a2ea4\u0022, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228530\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploit_attempt\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8530","http_user_agent":"Mozilla\/5.0 (X11; Linux x86_64; rv:142.0) Gecko\/20100101 Firefox\/142.0","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":161},{"id":8428030,"ip":"184.105.247.195","ts":"2026-06-07 02:20:54.000000","proto":"tcp","src_port":7466,"dst_port":8531,"service":"tls","classification":"postgres_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_sni\u0022: null, \u0022tls_weak_cipher\u0022: true, \u0022tls_weak_cipher_count\u0022: 6, \u0022bytes_in\u0022: 128, \u0022payload_entropy\u0022: 4.785207120154468, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 8531, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 43.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 6, \u0022risk_granularity\u0022: 2.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002266fa9b3a8209916c8dd0ae0b7e9df3a8210ba4db\u0022, \u0022event_fingerprint\u0022: \u002291dcaa7974b5467f9f5c469e879963e0ae9d8152\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.59, \u0022classification_confidence\u0022: 0.59, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0369\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0369\u0022], \u0022matched_patterns\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022PostgreSQL startup\u0022, \u0022Minecraft varint handshake\u0022, \u0022SOCKS5 greeting\u0022, \u0022SIP TLS ClientHello\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35, \u0022correlation_boost\u0022: 10}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022tls\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022payload_hash\u0022: \u0022b58d3eadcd193dd10eb830bf634002b6\u0022, \u0022path_pattern_hash\u0022: \u002280f3c71fe26f36a0a9399108643f66c5\u0022, \u0022ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8531, \u0022service\u0022: \u0022tls\u0022, \u0022service_name\u0022: \u0022tls\u0022, \u0022risk_score\u0022: 35}, \u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003v\ufffd\ufffd\\n\u0407\u02d6\\u0019\ufffd\ufffd\ufffd\\\u0022\ufffd\\u001e\ufffd6\ufffd\ufffd\ufffd\\\u0022\\u0002\ufffd\ufffd\ufffdc\ufffd\\u000e\ufffd\ufffd\ufffd\\r\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003v\ufffd\ufffd\\n\u0407\u02d6\\u0019\ufffd\ufffd\ufffd\\\u0022\ufffd\\u001e\ufffd6\ufffd\ufffd\ufffd\\\u0022\\u0002\ufffd\ufffd\ufffdc\ufffd\\u000e\ufffd\ufffd\ufffd\\r\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003v\ufffd\ufffd\\n\u0407\u02d6\\u0019\ufffd\ufffd\ufffd\\\u0022\ufffd\\u001e\ufffd6\ufffd\ufffd\ufffd\\\u0022\\u0002\ufffd\ufffd\ufffdc\ufffd\\u000e\ufffd\ufffd\ufffd\\r\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003v\ufffd\ufffd\\n\u0407\u02d6\\u0019\ufffd\ufffd\ufffd\\\u0022\ufffd\\u001e\ufffd6\ufffd\ufffd\ufffd\\\u0022\\u0002\ufffd\ufffd\ufffdc\ufffd\\u000e\ufffd\ufffd\ufffd\\r\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003v\ufffd\ufffd\\n\u0407\u02d6\\u0019\ufffd\ufffd\ufffd\\\u0022\ufffd\\u001e\ufffd6\ufffd\ufffd\ufffd\\\u0022\\u0002\ufffd\ufffd\ufffdc\ufffd\\u000e\ufffd\ufffd\ufffd\\r\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00227bf45b4b954a3af1d64db0d5720d7f8e8aaccebf\u0022, \u0022tls_ja3\u0022: \u0022771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0\u0022, \u0022tls_ja4_hash\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_ja4\u0022: \u0022t13d0113_ad3470b4f447_40d2e578a3e2\u0022, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022tls\u0022, \u0022service_banner\u0022: \u0022honeypot-tls\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228531\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022coordinated_scan\u0022: true, \u0022coordinated_subnet\u0022: \u0022184.105.247.0\/24\u0022, \u0022coordinated_ip_count\u0022: 3, \u0022behavior_alerts\u0022: [\u0022coordinated_scan\u0022], \u0022correlation_confidence_boost\u0022: 10, \u0022attack_chain_stage\u0022: \u0022probe\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022]}","tls_sni":null,"tls_ja3_hash":"cba7f34191ef2379c1325641f6c6c4f4","tls_ja3":"771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022]","anomalies":"[]","severity":4,"bytes_in":128},{"id":8428016,"ip":"184.105.247.195","ts":"2026-06-07 02:20:35.000000","proto":"tcp","src_port":36230,"dst_port":8531,"service":"tls","classification":"postgres_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_sni\u0022: null, \u0022tls_weak_cipher\u0022: true, \u0022tls_weak_cipher_count\u0022: 6, \u0022bytes_in\u0022: 128, \u0022payload_entropy\u0022: 4.7836467221840016, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 8531, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 43.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 6, \u0022risk_granularity\u0022: 2.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002266fa9b3a8209916c8dd0ae0b7e9df3a8210ba4db\u0022, \u0022event_fingerprint\u0022: \u002291dcaa7974b5467f9f5c469e879963e0ae9d8152\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.59, \u0022classification_confidence\u0022: 0.59, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0369\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0369\u0022], \u0022matched_patterns\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022PostgreSQL startup\u0022, \u0022Minecraft varint handshake\u0022, \u0022SOCKS5 greeting\u0022, \u0022SIP TLS ClientHello\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35, \u0022correlation_boost\u0022: 10}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022tls\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022payload_hash\u0022: \u0022a9be9da4c5dfef31f115145e880446bb\u0022, \u0022path_pattern_hash\u0022: \u002280f3c71fe26f36a0a9399108643f66c5\u0022, \u0022ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8531, \u0022service\u0022: \u0022tls\u0022, \u0022service_name\u0022: \u0022tls\u0022, \u0022risk_score\u0022: 35}, \u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\/$\ufffd~\\u0004\ufffd\ufffd\u0027q\\u000f\ufffd0od3$\\b\ufffd\ufffd\\t\ufffd\ufffdx\\r\u03e8\\u001d\ufffd\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\/$\ufffd~\\u0004\ufffd\ufffd\u0027q\\u000f\ufffd0od3$\\b\ufffd\ufffd\\t\ufffd\ufffdx\\r\u03e8\\u001d\ufffd\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\/$\ufffd~\\u0004\ufffd\ufffd\u0027q\\u000f\ufffd0od3$\\b\ufffd\ufffd\\t\ufffd\ufffdx\\r\u03e8\\u001d\ufffd\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\/$\ufffd~\\u0004\ufffd\ufffd\u0027q\\u000f\ufffd0od3$\\b\ufffd\ufffd\\t\ufffd\ufffdx\\r\u03e8\\u001d\ufffd\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\/$\ufffd~\\u0004\ufffd\ufffd\u0027q\\u000f\ufffd0od3$\\b\ufffd\ufffd\\t\ufffd\ufffdx\\r\u03e8\\u001d\ufffd\ufffd\ufffd\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022aab8b617bbbac83f14934286c8d50d29e6b40cd4\u0022, \u0022tls_ja3\u0022: \u0022771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0\u0022, \u0022tls_ja4_hash\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_ja4\u0022: \u0022t13d0113_ad3470b4f447_40d2e578a3e2\u0022, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022tls\u0022, \u0022service_banner\u0022: \u0022honeypot-tls\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228531\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022coordinated_scan\u0022: true, \u0022coordinated_subnet\u0022: \u0022184.105.247.0\/24\u0022, \u0022coordinated_ip_count\u0022: 3, \u0022behavior_alerts\u0022: [\u0022coordinated_scan\u0022], \u0022correlation_confidence_boost\u0022: 10, \u0022attack_chain_stage\u0022: \u0022probe\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022]}","tls_sni":null,"tls_ja3_hash":"cba7f34191ef2379c1325641f6c6c4f4","tls_ja3":"771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022]","anomalies":"[]","severity":4,"bytes_in":128},{"id":8427945,"ip":"184.105.247.195","ts":"2026-06-07 02:19:16.000000","proto":"tcp","src_port":21316,"dst_port":8531,"service":"tls","classification":"postgres_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_sni\u0022: null, \u0022tls_weak_cipher\u0022: true, \u0022tls_weak_cipher_count\u0022: 6, \u0022bytes_in\u0022: 128, \u0022payload_entropy\u0022: 4.787476604962698, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 8531, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 43.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 6, \u0022risk_granularity\u0022: 2.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002266fa9b3a8209916c8dd0ae0b7e9df3a8210ba4db\u0022, \u0022event_fingerprint\u0022: \u002291dcaa7974b5467f9f5c469e879963e0ae9d8152\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0369\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0369\u0022], \u0022matched_patterns\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022PostgreSQL startup\u0022, \u0022Minecraft varint handshake\u0022, \u0022SOCKS5 greeting\u0022, \u0022SIP TLS ClientHello\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0369\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022tls\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022ja3\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022payload_hash\u0022: \u0022ba230bb396c2cad765f884570be77f1f\u0022, \u0022path_pattern_hash\u0022: \u002280f3c71fe26f36a0a9399108643f66c5\u0022, \u0022ja4\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8531, \u0022service\u0022: \u0022tls\u0022, \u0022service_name\u0022: \u0022tls\u0022, \u0022risk_score\u0022: 35}, \u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\ufffd\ufffd\u8172x\ufffd\ufffd\\t\ufffd\u0558-\ufffd\ufffd\ufffd+\ufffd\\u0018\/\ufffd1\u0101\ufffd|5(\ufffd\\t\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\ufffd\ufffd\u8172x\ufffd\ufffd\\t\ufffd\u0558-\ufffd\ufffd\ufffd+\ufffd\\u0018\/\ufffd1\u0101\ufffd|5(\ufffd\\t\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\ufffd\ufffd\u8172x\ufffd\ufffd\\t\ufffd\u0558-\ufffd\ufffd\ufffd+\ufffd\\u0018\/\ufffd1\u0101\ufffd|5(\ufffd\\t\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\ufffd\ufffd\u8172x\ufffd\ufffd\\t\ufffd\u0558-\ufffd\ufffd\ufffd+\ufffd\\u0018\/\ufffd1\u0101\ufffd|5(\ufffd\\t\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000{\\u0001\\u0000\\u0000w\\u0003\\u0003\ufffd\ufffd\ufffd\u8172x\ufffd\ufffd\\t\ufffd\u0558-\ufffd\ufffd\ufffd+\ufffd\\u0018\/\ufffd1\u0101\ufffd|5(\ufffd\\t\\u0000\\u0000\\u001a\ufffd\/\ufffd+\ufffd\\u0011\ufffd\\u0007\ufffd\\u0013\ufffd\\t\ufffd\\u0014\ufffd\\n\\u0000\\u0005\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0001\\u0000\\u00004\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u0010\\u0000\\u000e\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\ufffd\\u0001\\u0000\\u0001\\u0000\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022e7da4bac0ae337e734f16fd772ef6705c127775f\u0022, \u0022tls_ja3\u0022: \u0022771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0\u0022, \u0022tls_ja4_hash\u0022: \u0022a3a5f53d3656a0df675e8aa020d5979e\u0022, \u0022tls_ja4\u0022: \u0022t13d0113_ad3470b4f447_40d2e578a3e2\u0022, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022tls\u0022, \u0022service_banner\u0022: \u0022honeypot-tls\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228531\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022probe\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022]}","tls_sni":null,"tls_ja3_hash":"cba7f34191ef2379c1325641f6c6c4f4","tls_ja3":"771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022]","anomalies":"[]","severity":4,"bytes_in":128},{"id":8310210,"ip":"184.105.247.195","ts":"2026-06-05 10:56:35.000000","proto":"tcp","src_port":51748,"dst_port":81,"service":"http","classification":"exploit_attempt","waf_score":13,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022]","http_method":"CONNECT","http_target":"www.shadowserver.org:443","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 5, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u00225186dac1dd506c3487aa39a6c8a4a57637399ef6\u0022, \u0022http_host_hash\u0022: \u00226ae3ed4621d9c0dd8cee74f6b1c5b4073913b336\u0022, \u0022http_target_hash\u0022: \u00226b8e04bac019a1bdc3bcbdaa5cdd24320a9a648d\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022CONNECT\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 273, \u0022payload_entropy\u0022: 5.408993570259432, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 81, \u0022risk_waf\u0022: 60.0, \u0022risk_classification\u0022: 72.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.4, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 60.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002239d5c7a66ecbe92065e4bf265cf3db12502075a8\u0022, \u0022event_fingerprint\u0022: \u0022e325ad123984696a35589d8900e8bce207826272\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022confidence\u0022: 0.62, \u0022classification_confidence\u0022: 0.62, \u0022precision_score\u0022: 73, \u0022precision_signals\u0022: [\u0022MITRE-T1190\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1190\u0022], \u0022risk_confidence_factor\u0022: 62.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022efff31ee849c981a7783b6add0cf22b7\u0022, \u0022payload_hash\u0022: \u0022aabdf92aa4de33ecfd336cfa20d3b1be\u0022, \u0022path_pattern_hash\u0022: \u0022a0d39411cb42eec21469d044e2155f68\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 81, \u0022service\u0022: \u0022http\u0022}, \u0022payload_preview\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) App\u0022, \u0022method\u0022: \u0022CONNECT\u0022, \u0022path\u0022: \u0022www.shadowserver.org:443\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022], \u0022request_line\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\\r\\nConnection: Keep-Alive\\r\\nPragma: no-cache\\r\\nProxy-Connectio\u0022, \u0022payload_snippet\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) App\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022CONNECT\u0022, \u0022path\u0022: \u0022www.shadowserver.org:443\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022], \u0022request_line\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\\r\\nConnection: Keep-Alive\\r\\nPragma: no-cache\\r\\nProxy-Connectio\u0022, \u0022payload_snippet\u0022: \u0022CONNECT www.shadowserver.org:443 HTTP\/1.1\\r\\nHost: www.shadowserver.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) App\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022f505550c78ad6aeadfeed3f5bcbad7479ee92203\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022http_dangerous_method\u0022, \u0022http_method_uncommon\u0022], \u0022behavior_alert_count\u0022: 1, \u0022behavior_priority\u0022: 96}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"www.shadowserver.org","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022http_dangerous_method\u0022, \u0022http_method_uncommon\u0022]","anomalies":"[]","severity":7,"bytes_in":273},{"id":8310209,"ip":"184.105.247.195","ts":"2026-06-05 10:56:29.000000","proto":"tcp","src_port":39722,"dst_port":81,"service":"http","classification":"web_probe","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"http:\/\/api.ipify.org\/?format=json","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 2, \u0022http_query_params\u0022: 1, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u00225186dac1dd506c3487aa39a6c8a4a57637399ef6\u0022, \u0022http_host_hash\u0022: \u0022d29a2ecf00a8df01957221d1f0dff7b5d932ee52\u0022, \u0022http_target_hash\u0022: \u0022c992eafe99bb93048b184fe302c46a2c7c06d83d\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 199, \u0022payload_entropy\u0022: 5.432339101056475, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 81, \u0022risk_waf\u0022: 72.0, \u0022risk_classification\u0022: 48.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.4, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 48.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 39, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00224d4db57eb16fb0d21eecb9f6199a74aecb5dbb82\u0022, \u0022event_fingerprint\u0022: \u0022a6c47c3004a8dfaa78cdbb46eaeca4733e2bc663\u0022, \u0022classification_reason\u0022: \u0022Sonde HTTP (tag rce-0) \u00b7 confiance 34%\u0022, \u0022confidence\u0022: 0.34, \u0022classification_confidence\u0022: 0.34, \u0022precision_score\u0022: 40, \u0022precision_signals\u0022: [\u0022INT-single-port\u0022], \u0022kb_rule_ids\u0022: [\u0022INT-single-port\u0022], \u0022matched_patterns\u0022: [\u0022pat-0103\u0022], \u0022matched_pattern_names\u0022: [\u0022LFI Double-dot bypass\u0022], \u0022pattern_ids\u0022: [\u0022pat-0103\u0022], \u0022risk_confidence_factor\u0022: 34.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022efff31ee849c981a7783b6add0cf22b7\u0022, \u0022payload_hash\u0022: \u00221030f989cb9522423f292a24da3e4a68\u0022, \u0022path_pattern_hash\u0022: \u00229e6886b350be931fd969e2abc3b79698\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 81, \u0022service\u0022: \u0022http\u0022}, \u0022payload_preview\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) Apple\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022query_string\u0022: \u0022format=json\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) Apple\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022query_string\u0022: \u0022format=json\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET http:\/\/api.ipify.org\/?format=json HTTP\/1.1\\r\\nHost: api.ipify.org\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) Apple\u0022, \u0022classification_reason\u0022: \u0022Sonde HTTP (tag rce-0) \u00b7 confiance 34%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022d43cb68149f2e2fd49a134aac1edeae256af01cb\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_absolute_uri\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"api.ipify.org","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/99.0.4844.84 Safari\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_absolute_uri\u0022]","anomalies":"[]","severity":8,"bytes_in":199},{"id":8310184,"ip":"184.105.247.195","ts":"2026-06-05 10:54:56.000000","proto":"tcp","src_port":38700,"dst_port":81,"service":"http","classification":"exploit_attempt","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022940ef98c80932a8517b4241839e8e9d3b1f40c6b\u0022, \u0022http_host_hash\u0022: \u0022f257870e26046e30cbd03e9d5726ca53aa58b86f\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 190, \u0022payload_entropy\u0022: 5.433418525901138, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 81, \u0022risk_waf\u0022: 72.0, \u0022risk_classification\u0022: 72.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 25.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.1, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 25.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 46, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002203a690d60596d39f0632dad68ca29347a0b65b81\u0022, \u0022event_fingerprint\u0022: \u0022ea594d22610095fdc4d5a1f374bfd407e5255a96\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022confidence\u0022: 0.62, \u0022classification_confidence\u0022: 0.62, \u0022precision_score\u0022: 73, \u0022precision_signals\u0022: [\u0022MITRE-T1190\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1190\u0022], \u0022risk_confidence_factor\u0022: 62.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022ac8f5c88a83e672485247380c0afada5\u0022, \u0022payload_hash\u0022: \u0022d3b02b49e41ef34828835a3cd7bd0205\u0022, \u0022path_pattern_hash\u0022: \u00228a5edab282632443219e051e4ade2d1d\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 81, \u0022service\u0022: \u0022http\u0022}, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:81\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/1\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/126.0.0.0 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:81\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/126.0.0.0 Safari\/537.36\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:81\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/1\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/126.0.0.0 Safari\/537.36\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:81\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/126.0.0.0 Safari\/537.36\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:81\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/1\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022c1e4a9a67ad49258a1efecdc9217b8e97f015ac1\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:81","http_user_agent":"Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/126.0.0.0 Safari\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":190},{"id":8233035,"ip":"184.105.247.195","ts":"2026-06-04 15:17:26.000000","proto":"tcp","src_port":4436,"dst_port":21,"service":"ftp","classification":"ftp_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 0, \u0022payload_entropy\u0022: 0.0, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022ftp\u0022, \u0022app_proto\u0022: \u0022ftp\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 21, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 30.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 0.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.4, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 30.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 0.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 13, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022a17acc8e03b7181b98dcfcea5c1988992b5edc3c\u0022, \u0022event_fingerprint\u0022: \u0022ffa420b3a4312f33d6282bce2ed7401eccb1b74e\u0022, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022path_pattern_hash\u0022: \u0022927e5cb33ffc245351b0aac1c306b95c\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 21, \u0022service\u0022: \u0022ftp\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022confidence\u0022: 0.65, \u0022classification_confidence\u0022: 0.65, \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022007ecd8f47e7cb9e977cd0b265d8c0c565bd38b5\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":4,"bytes_in":0},{"id":8191347,"ip":"184.105.247.195","ts":"2026-06-04 08:38:18.000000","proto":"tcp","src_port":42540,"dst_port":8880,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022c5f2247a66bd146d7a3c8a5b66f02126669f9be8\u0022, \u0022http_host_hash\u0022: \u0022705e57393925ae4499d6cc481be3dac8642e294d\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 259, \u0022payload_entropy\u0022: 5.4543459245940635, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 8880, \u0022risk_waf\u0022: 72.0, \u0022risk_classification\u0022: 80.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 25.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 80.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 25.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 47, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022e7eb56cd0ccee6035fab80aaeca04c7a8880029e\u0022, \u0022event_fingerprint\u0022: \u00229c43302bad8d79f2a58d5038033b2ff224a2b508\u0022, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u002263b67b41e7ebd7450c833e3946ae719b\u0022, \u0022payload_hash\u0022: \u0022418bb1b3b649fdb0c929f6ebf225ce3c\u0022, \u0022path_pattern_hash\u0022: \u00228a5edab282632443219e051e4ade2d1d\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8880, \u0022service\u0022: \u0022http\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022confidence\u0022: 0.89, \u0022classification_confidence\u0022: 0.89, \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:8880\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0.0; Win64; x64; ) AppleWebKit\/537.36 (KHTML, like\u0022, \u0022event_signature\u0022: \u0022bdd52b66bb866e6a75e3f385ba14b86987593a10\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8880","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0.0; Win64; x64; ) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/122.0.6261.156 Not(A:Brand\/24 YaBrowser\/24.4.1.899 Yowser\/2.5  Safari\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":259},{"id":8180987,"ip":"184.105.247.195","ts":"2026-06-04 04:21:44.000000","proto":"tcp","src_port":14404,"dst_port":1000,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u00221b55bb2b2c31a214be7c6f16fefa5e6629cee38b\u0022, \u0022http_host_hash\u0022: \u0022f258a94e90e1893d77a4333d1c37930c29020403\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 208, \u0022payload_entropy\u0022: 5.296580944027448, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 1000, \u0022risk_waf\u0022: 72.0, \u0022risk_classification\u0022: 80.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 25.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 80.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 25.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 46, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022d3781e0bbb7b3eaae9d315ddc3d54861b06e4ffb\u0022, \u0022event_fingerprint\u0022: \u00229781a8e1f03c20706a3c9dc8a1e2e6145feea827\u0022, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u002213fd361c984c8bedd01d045cc371ca74\u0022, \u0022payload_hash\u0022: \u0022b1e1fcea0f12da91576a0361cb16366e\u0022, \u0022path_pattern_hash\u0022: \u00228a5edab282632443219e051e4ade2d1d\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 1000, \u0022service\u0022: \u0022http\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022confidence\u0022: 0.89, \u0022classification_confidence\u0022: 0.89, \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:1000\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit\/605.1.15 (KHTML, \u0022, \u0022event_signature\u0022: \u00224d4ccbaae11b0b55fbe575731990530cb0e4cc66\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:1000","http_user_agent":"Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit\/605.1.15 (KHTML, like Gecko) Version\/16.1 Safari\/605.1.15","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":208},{"id":8176688,"ip":"184.105.247.195","ts":"2026-06-04 02:07:55.000000","proto":"tcp","src_port":15516,"dst_port":7000,"service":null,"classification":"port_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 0, \u0022payload_entropy\u0022: 0.0, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 7000, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 30.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 0.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 30.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 0.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 14, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022107e9ada1d194d25fd01cd3c7cb77dc57c418a73\u0022, \u0022event_fingerprint\u0022: \u00229c55ccff0a4cdad51c3d2ef4842ed8f0413ff78a\u0022, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 6939, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022path_pattern_hash\u0022: \u002249ebffbc8eed300cf9429db1ba4cf66d\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 7000}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022confidence\u0022: 0.55, \u0022classification_confidence\u0022: 0.55, \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00222727f8458a07a7243d298433389c09cbf769f771\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":0,"bytes_in":0},{"id":8121297,"ip":"184.105.247.195","ts":"2026-06-01 12:34:34.000000","proto":"tcp","src_port":40514,"dst_port":5432,"service":"postgres","classification":"postgres_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 8, \u0022payload_entropy\u0022: 2.4056390622295662, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022postgres\u0022, \u0022app_proto\u0022: \u0022postgres\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 72, \u0022campaign_key\u0022: \u0022df55e61bc85914b72878400009774ae02ad66b00\u0022, \u0022event_fingerprint\u0022: \u00224138d14bd0667084fff53c3dcdd9f6c899426984\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":6,"bytes_in":8},{"id":8084180,"ip":"184.105.247.195","ts":"2026-06-01 06:34:20.000000","proto":"tcp","src_port":18055,"dst_port":5081,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u002235fa0a83e466acbec1cfbb9016d550ab\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 243, \u0022payload_entropy\u0022: 5.860114631567195, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022567a489ca2f5dd4c1a65b748570161327ac85a9c\u0022, \u0022event_fingerprint\u0022: \u00227fe42a0a69632886fc5318c069426a0267648b44\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"35fa0a83e466acbec1cfbb9016d550ab","tls_ja3":"771,52392-52393-49199-49200-49195-49196-49171-49161-49172-49162-156-157-47-53-49170-10-4867-4865-4866,5-10-11-13-65281-18-43-51,29-23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":243},{"id":8084178,"ip":"184.105.247.195","ts":"2026-06-01 06:34:14.000000","proto":"tcp","src_port":29088,"dst_port":5081,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 128, \u0022payload_entropy\u0022: 4.874301328502067, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022567a489ca2f5dd4c1a65b748570161327ac85a9c\u0022, \u0022event_fingerprint\u0022: \u0022af62f5dd8085f07b3c1191ce3dab128da9980d61\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"cba7f34191ef2379c1325641f6c6c4f4","tls_ja3":"771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":128},{"id":8083501,"ip":"184.105.247.195","ts":"2026-06-01 06:06:02.000000","proto":"tcp","src_port":39028,"dst_port":20020,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022803bc2bca1669a5180ebd764449026907ba3c1d9\u0022, \u0022http_host_hash\u0022: \u00227c910635ebdd2ec7a02b91e4a18506786608faa0\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 193, \u0022payload_entropy\u0022: 5.427703935492988, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u00226c733cdc76068babe944cdaa0041b8f7ac86f8b5\u0022, \u0022event_fingerprint\u0022: \u00227f506b7e79e18b41f6b7751259206c3b928342a9\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:20020","http_user_agent":"Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/108.0.0.0 Safari\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":193},{"id":8069510,"ip":"184.105.247.195","ts":"2026-06-01 01:35:07.000000","proto":"tcp","src_port":65068,"dst_port":22,"service":"ssh","classification":"ssh_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 0, \u0022payload_entropy\u0022: 0.0, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022ssh\u0022, \u0022app_proto\u0022: \u0022ssh\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 72, \u0022campaign_key\u0022: \u00228002f2599f5e7264fe48cbfe5f827b3747776541\u0022, \u0022event_fingerprint\u0022: \u002202d08c71c151699ccee46f4659d4205cd9a77e2d\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":6,"bytes_in":0},{"id":8047755,"ip":"184.105.247.195","ts":"2026-05-31 14:45:01.000000","proto":"tcp","src_port":23772,"dst_port":6001,"service":null,"classification":"port_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 0, \u0022payload_entropy\u0022: 0.0, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 0, \u0022campaign_key\u0022: \u00221f847ad034c28c80ddac821ec51c9139e8cee640\u0022, \u0022event_fingerprint\u0022: \u00227263e569890360e5f710791fe3db7523d15ce799\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":0,"bytes_in":0},{"id":8046960,"ip":"184.105.247.195","ts":"2026-05-31 14:23:15.000000","proto":"tcp","src_port":51450,"dst_port":5900,"service":"vnc","classification":"vnc_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 0, \u0022payload_entropy\u0022: 0.0, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022vnc\u0022, \u0022app_proto\u0022: \u0022vnc\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 72, \u0022campaign_key\u0022: \u00225011565089e10a7b17fd6bcb0a986cc85d417fbe\u0022, \u0022event_fingerprint\u0022: \u00221156aedf4513e5bd7708e4e21958cd8af973e20d\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":6,"bytes_in":0},{"id":8039069,"ip":"184.105.247.195","ts":"2026-05-31 11:25:02.000000","proto":"tcp","src_port":12676,"dst_port":8060,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u002206c6936bd2e49babc5d8cff65b916d05fe9bff95\u0022, \u0022http_host_hash\u0022: \u0022659aba210ed45d12732dc398ec420869b9d4d3d3\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 171, \u0022payload_entropy\u0022: 5.215982902276219, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u002240f8eae1b445cdb4a80ebb40d215798791b6e7d5\u0022, \u0022event_fingerprint\u0022: \u00227da49a81a68aba93eb39f88e14f73ed92b3f3fc9\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8060","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko\/20100101 Firefox\/116.0","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":171},{"id":7997871,"ip":"184.105.247.195","ts":"2026-05-30 14:17:03.000000","proto":"tcp","src_port":50036,"dst_port":1801,"service":null,"classification":"port_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 572, \u0022payload_entropy\u0022: 1.0235077004147528, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 0, \u0022campaign_key\u0022: \u0022103330084a959f094e084cc9d4da7fd069b99528\u0022, \u0022event_fingerprint\u0022: \u00224dec48a3260c0c5fc678059aabce6164677b08e6\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":0,"bytes_in":572},{"id":7988222,"ip":"184.105.247.195","ts":"2026-05-30 09:05:02.000000","proto":"tcp","src_port":36794,"dst_port":9643,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022724d5a8254fa9d7e73475232630fca53bdbd0f90\u0022, \u0022http_host_hash\u0022: \u0022cb1afac92f3620b49934d6e5ac11caee8c12ebf3\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 208, \u0022payload_entropy\u0022: 5.359369546649175, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022366915b90f9520f9cdb6c4fa616f52a6846719c4\u0022, \u0022event_fingerprint\u0022: \u00226e0ee1b8626e7b8c925a42af4ffc61da1ffb41b2\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:9643","http_user_agent":"Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit\/605.1.15 (KHTML, like Gecko) Version\/17.6 Safari\/605.1.15","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":208},{"id":7928871,"ip":"184.105.247.195","ts":"2026-05-29 08:49:48.000000","proto":"tcp","src_port":7056,"dst_port":9999,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u002218944bf9c08954c4ab2443438e9bd9a12eea6679\u0022, \u0022http_host_hash\u0022: \u002283a22baaf629d53e39c79d30e6b18dca9da1a92c\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 205, \u0022payload_entropy\u0022: 5.414049510933064, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022c992bf4a8142641692d5115f793db7285de35d61\u0022, \u0022event_fingerprint\u0022: \u00225823f7ce3e55ab30127f12cd1e8a81fbeb0285d8\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:9999","http_user_agent":"Mozilla\/5.0 (Macintosh; Intel Mac OS X 14_4) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/123.0.0.0 Safari\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":205},{"id":7878474,"ip":"184.105.247.195","ts":"2026-05-28 11:35:53.000000","proto":"tcp","src_port":47638,"dst_port":4646,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u00228ce2ac0889d881e6b69dfc50d026374b84fe6254\u0022, \u0022http_host_hash\u0022: \u002246a9b2ce10e9d611ee86e145e07ad2eb86ad6ce6\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 208, \u0022payload_entropy\u0022: 5.3374697554859845, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022279482ce20f6824739f6b910de27566a2ce129e7\u0022, \u0022event_fingerprint\u0022: \u00223871cb319ce7317be83387db082a249c91011d37\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:4646","http_user_agent":"Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit\/605.1.15 (KHTML, like Gecko) Version\/16.0 Safari\/605.1.15","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":208},{"id":7863335,"ip":"184.105.247.195","ts":"2026-05-28 06:00:18.000000","proto":"tcp","src_port":16264,"dst_port":2096,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u002235fa0a83e466acbec1cfbb9016d550ab\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 243, \u0022payload_entropy\u0022: 5.8718852545740985, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022e696b1832062c195486678d72a74d288886e2102\u0022, \u0022event_fingerprint\u0022: \u00220b668443e33b05d993c291dd50aecf3e5d7322f7\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"35fa0a83e466acbec1cfbb9016d550ab","tls_ja3":"771,52392-52393-49199-49200-49195-49196-49171-49161-49172-49162-156-157-47-53-49170-10-4867-4865-4866,5-10-11-13-65281-18-43-51,29-23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":243},{"id":7863197,"ip":"184.105.247.195","ts":"2026-05-28 05:59:37.000000","proto":"tcp","src_port":16242,"dst_port":2096,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 128, \u0022payload_entropy\u0022: 4.841809561543816, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022e696b1832062c195486678d72a74d288886e2102\u0022, \u0022event_fingerprint\u0022: \u0022e0ecbf1fd94f0b3567566ed3473a9e9d1680183c\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"cba7f34191ef2379c1325641f6c6c4f4","tls_ja3":"771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":128},{"id":7808624,"ip":"184.105.247.195","ts":"2026-05-27 14:49:59.000000","proto":"tcp","src_port":40174,"dst_port":5672,"service":"amqp","classification":"amqp_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 8, \u0022payload_entropy\u0022: 2.75, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022amqp\u0022, \u0022app_proto\u0022: \u0022amqp\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 50, \u0022campaign_key\u0022: \u0022c3e18ab96daf5210e045e84efeb3e26b0cfb0c98\u0022, \u0022event_fingerprint\u0022: \u0022b0beb8729344e0fecf193ea4915355ace522129f\u0022, \u0022tags_list\u0022: [\u0022amqp_handshake\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022amqp_handshake\u0022]","anomalies":"[]","severity":4,"bytes_in":8},{"id":7778725,"ip":"184.105.247.195","ts":"2026-05-27 06:40:23.000000","proto":"tcp","src_port":51774,"dst_port":1003,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 128, \u0022payload_entropy\u0022: 4.888684561543816, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022e55037104f11ca07fd05219f98ad55aaffd472c1\u0022, \u0022event_fingerprint\u0022: \u00228272f9533c69e703a1120d88594f25cc7d98d590\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"cba7f34191ef2379c1325641f6c6c4f4","tls_ja3":"771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":128},{"id":7777363,"ip":"184.105.247.195","ts":"2026-05-27 05:43:35.000000","proto":"tcp","src_port":39110,"dst_port":81,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022224532780fe2e707ad4c403542e7306b48753b17\u0022, \u0022http_host_hash\u0022: \u0022f257870e26046e30cbd03e9d5726ca53aa58b86f\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 199, \u0022payload_entropy\u0022: 5.393639367241509, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022d75923a08043500eae66386b467275bec1ed7723\u0022, \u0022event_fingerprint\u0022: \u002203badc3551a4f44339f123528b3672cbfed8ce84\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:81","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/134.0.0.0 Safari\/537.3","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":199},{"id":7753601,"ip":"184.105.247.195","ts":"2026-05-26 11:39:40.000000","proto":"tcp","src_port":36174,"dst_port":5002,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022cba7f34191ef2379c1325641f6c6c4f4\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 128, \u0022payload_entropy\u0022: 4.914037002933164, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022232bb2a578e422d3ab17dd028fde525e309629fe\u0022, \u0022event_fingerprint\u0022: \u00229effcffab68bcc6808bd0b854a03593af7cb7f7e\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"cba7f34191ef2379c1325641f6c6c4f4","tls_ja3":"771,49199-49195-49169-49159-49171-49161-49172-49162-5-47-53-49170-10,5-10-11-13-65281,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":128},{"id":7714970,"ip":"184.105.247.195","ts":"2026-05-25 14:31:33.000000","proto":"tcp","src_port":13186,"dst_port":33060,"service":null,"classification":"port_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 0, \u0022payload_entropy\u0022: 0.0, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Hurricane Electric LLC\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 6939, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 0, \u0022campaign_key\u0022: \u00221a60bfb0fe7cdef8390f54a300bc8c79cbf51349\u0022, \u0022event_fingerprint\u0022: \u00220f9e3ebe615d571f655c7a12ad6c5f6e2913dd5f\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":0,"bytes_in":0}],"total_events":84}