{"ip":"198.235.24.240","exported_at":"2026-06-17T00:06:57+00:00","period_days":30,"metrics":{"events7d":1,"distinct_ports":1,"distinct_classifications":1,"max_severity":5,"last_sensor_id":"paris-1","max_waf_score":null,"max_risk_score":100,"attack_stage":"probe","attack_chain_stage":"discovery","threat_family":["scanner"],"recommended_action":"monitor","confidence":0.5,"risk_breakdown":{"waf":8,"classification":47,"behavior":0,"geo":40,"protocol":40,"novelty":15},"mitre_tactics":["TA0007","TA0001"],"mitre_technique":"TA0007","top_mitre_technique":"TA0007","top_mitre_count":7,"executive_one_liner_fr":"Activit\u00e9 suspecte \u00b7 risque 45\/100","campaign_hint_fr":null,"confidence_breakdown":{"waf":8,"classification":47,"behavior":0,"geo":40,"protocol":40,"novelty":15,"risk_score":45},"persona_hostname":"mail.sensor-1.internal","correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":50,"confidence_hint_fr":"Confiance mod\u00e9r\u00e9e \u2014 signal unique","sensor_role_label_fr":"Renseignement menaces","tags_summary_labels_fr":["pat-0460"],"tags_summary":["pat-0460"],"attack_vector":"smtp probe \u00b7 via SMTP SUBMISSION:587 \u00b7 (sonde \/ probe)","protocol_details":{"smtp_auth_fr":"Sonde protocole SMTP","payload_preview":"GET \/ HTTP\/1.1\r\nHost: 62.3.50.33:587\r\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-c","port":587,"service":"smtp-submission","service_label_fr":"SMTP SUBMISSION"},"protocol_summary_fr":"Sonde protocole SMTP \u00b7 Payload GET \/ HTTP\/1.1\r\nHost: 62.3.50.33:587\r\nUser-Agent: Hello from Pa\u2026 \u00b7 SMTP SUBMISSION:587","evidence_snippet":"GET \/ HTTP\/1.1\r\nHost: 62.3.50.33:587\r\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-c","target_port_label":"587 \u00b7 SMTP SUBMISSION","emulator_service":"smtp-submission","confidence_reason":"Confiance 50 % \u2014 Motif catalogue confirm\u00e9","classification_reason":"Type \u00ab smtp_probe \u00bb (signaux protocolaires) \u00b7 confiance 50%","classification_reason_label_fr":"Type \u00ab smtp_probe \u00bb (signaux protocolaires) \u00b7 confiance 50%","confidence_factors_fr":"Confiance 50 % \u2014 Score WAF 8","payload_preview":"GET \/ HTTP\/1.1\r\nHost: 62.3.50.33:587\r\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-c"},"events":[{"id":9419031,"ip":"198.235.24.240","ts":"2026-06-16 19:59:03.000000","proto":"tcp","src_port":64458,"dst_port":587,"service":"smtp-submission","classification":"smtp_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022323230206d61696c2e6578616d706c652e636f6d2045534d545020506f737466697820285562756e7475290d0a35303220352e352e32204572726f723a20636f6d6d616e64206e6f74207265636f676e697a65640d0a\u0022, \u0022emulator_response_len\u0022: 86, \u0022bytes_in\u0022: 217, \u0022payload_entropy\u0022: 5.1036331775748005, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022smtp-submission\u0022, \u0022app_proto\u0022: \u0022smtp-submission\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 587, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 47.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 6.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 47.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 45, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00224415fda42e223cd839ea474ee439b8524c421754\u0022, \u0022event_fingerprint\u0022: \u0022a4eb3bdaea671903d3ce718aa560d7f3c055f5fb\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022pat-0460\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab smtp_probe \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 47.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022service_name\u0022: \u0022smtp-submission\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022bf0d7be4b77432d9123db6d6b24fc1c1\u0022, \u0022path_pattern_hash\u0022: \u00220585f924ca84c34a681a0e1500b9f97a\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 587, \u0022service\u0022: \u0022smtp-submission\u0022, \u0022service_name\u0022: \u0022smtp-submission\u0022, \u0022risk_score\u0022: 45}, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:587\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-c\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:587\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks.com\/r\/1\/Cortex-Xpanse\/Scanning-activity\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:587\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-c\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:587\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks.com\/r\/1\/Cortex-Xpanse\/Scanning-activity\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:587\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-c\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab smtp_probe \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022bbd2e8e4759af236bc4e62eec099645f7fc1b9ab\u0022, \u0022protocol_details\u0022: {\u0022smtp_auth_fr\u0022: \u0022Sonde protocole SMTP\u0022, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:587\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-c\u0022, \u0022port\u0022: 587, \u0022service\u0022: \u0022smtp-submission\u0022, \u0022service_label_fr\u0022: \u0022SMTP SUBMISSION\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:587\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-c\u0022, \u0022attack_vector\u0022: \u0022smtp probe \u00b7 via SMTP SUBMISSION:587 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u0022587 \u00b7 SMTP SUBMISSION\u0022, \u0022emulator_service\u0022: \u0022smtp-submission\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab smtp_probe \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab smtp_probe \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 45\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 47.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 45}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 45, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022smtp-submission\u0022, \u0022service_label_fr\u0022: \u0022SMTP SUBMISSION\u0022, \u0022dst_port\u0022: 587, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0460\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0460\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-smtp-submission\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022smtp_auth_fr\u0022: \u0022Sonde protocole SMTP\u0022, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:587\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-c\u0022, \u0022port\u0022: 587, \u0022service\u0022: \u0022smtp-submission\u0022, \u0022service_label_fr\u0022: \u0022SMTP SUBMISSION\u0022}, \u0022attack_vector\u0022: \u0022smtp probe \u00b7 via SMTP SUBMISSION:587 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:587\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-c\u0022, \u0022target_port_label\u0022: \u0022587 \u00b7 SMTP SUBMISSION\u0022, \u0022emulator_service\u0022: \u0022smtp-submission\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022smtp_submission\u0022, \u0022service_banner\u0022: \u0022honeypot-smtp-submission\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u0022587\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022http_get_probe\u0022, \u0022mongodb_hello_probe\u0022, \u0022net_smtp_probe\u0022, \u0022smtp_emulated\u0022], \u0022asn_dc_heuristic\u0022: true, \u0022behavior_alert_count\u0022: 1, \u0022behavior_priority\u0022: 72}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022http_get_probe\u0022, \u0022mongodb_hello_probe\u0022, \u0022net_smtp_probe\u0022, \u0022smtp_emulated\u0022]","anomalies":"[]","severity":5,"bytes_in":217},{"id":8553563,"ip":"198.235.24.240","ts":"2026-06-08 05:50:39.000000","proto":"tcp","src_port":60168,"dst_port":10257,"service":"http","classification":"web_scanner","waf_score":23,"waf_tags":"[\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a5365727665723a204170616368652f322e342e35370d0a436f6e74656e742d4c656e6774683a20320d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a4f4b\u0022, \u0022emulator_response_len\u0022: 82, \u0022http_header_count\u0022: 3, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022689bfbab10519e1ecf247982c128c7460ee59d4d\u0022, \u0022http_host_hash\u0022: \u00222132f13275b966b13d6f20a0a04ff287b95961d2\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 219, \u0022payload_entropy\u0022: 5.108059523507308, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 10257, \u0022risk_waf\u0022: 57.5, \u0022risk_classification\u0022: 42.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 43.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 6.4, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 57.5, \u0022classification\u0022: 42.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 48, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022e7d7c71f846b9dd876c64dca0c43cdbb123e9bea\u0022, \u0022event_fingerprint\u0022: \u0022faced1cbee89050b68848d8b366c39eddb5d93eb\u0022, \u0022classification_reason\u0022: \u0022User-Agent scanner commercial d\u00e9clar\u00e9 \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 147, \u0022precision_signals\u0022: [\u0022INT-scanner-palo-alto\u0022, \u0022INT-upstream\u0022, \u0022INT-waf-score\u0022], \u0022kb_rule_ids\u0022: [\u0022INT-scanner-palo-alto\u0022, \u0022INT-upstream\u0022, \u0022INT-waf-score\u0022], \u0022matched_patterns\u0022: [\u0022pat-0103\u0022, \u0022pat-0460\u0022], \u0022matched_pattern_names\u0022: [\u0022LFI Double-dot bypass\u0022, \u0022UA Palo Alto Networks\u0022], \u0022pattern_ids\u0022: [\u0022pat-0103\u0022, \u0022pat-0460\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 57.5, \u0022classification\u0022: 42.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 48}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022ce3935d92be5f9290d282e51ab604b41\u0022, \u0022payload_hash\u0022: \u0022fd1657ba177b45fd0b8da139a7739559\u0022, \u0022path_pattern_hash\u0022: \u00228a5edab282632443219e051e4ade2d1d\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 10257, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 48}, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:10257\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022user_agent\u0022: \u0022Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks.com\/r\/1\/Cortex-Xpanse\/Scanning-activity\u0022, \u0022waf_tags\u0022: [\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022lfi-14\u0022, \u0022ssrf-3\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:10257\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks.com\/r\/1\/Cortex-Xpanse\/Scanning-activity\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:10257\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022user_agent\u0022: \u0022Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks.com\/r\/1\/Cortex-Xpanse\/Scanning-activity\u0022, \u0022waf_tags\u0022: [\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022lfi-14\u0022, \u0022ssrf-3\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:10257\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks.com\/r\/1\/Cortex-Xpanse\/Scanning-activity\\r\\nAccept-Encoding: gzip\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:10257\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs\u0022, \u0022classification_reason\u0022: \u0022User-Agent scanner commercial d\u00e9clar\u00e9 \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1595\u0022], \u0022mitre\u0022: \u0022T1595\u0022, \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022b620ad0e5dd0c92a99ba0ec97c2b16650e7a0e0c\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/\u0022, \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks.com\/r\/1\/Cortex-Xpa\u2026\u0022, \u0022port\u0022: 10257, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:10257\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs\u0022, \u0022attack_vector\u0022: \u0022web scanner \u00b7 via HTTP:10257 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002210257 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 4 tag(s) WAF\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022User-Agent scanner commercial d\u00e9clar\u00e9 \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022User-Agent scanner commercial d\u00e9clar\u00e9 \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 48\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 57.5, \u0022classification\u0022: 42.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 48}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 48, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 10257, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022INT-scanner-palo-alto\u0022, \u0022INT-upstream\u0022, \u0022INT-waf-score\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022Scanner Palo Alto\u0022, \u0022Upstream\u0022, \u0022Waf Score\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1595\u0022, \u0022mitre_technique\u0022: \u0022T1595\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022kube-controller-manager\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/\u0022, \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks.com\/r\/1\/Cortex-Xpa\u2026\u0022, \u0022port\u0022: 10257, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022web scanner \u00b7 via HTTP:10257 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:10257\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs\u0022, \u0022target_port_label\u0022: \u002210257 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 4 tag(s) WAF\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 57 \u00b7 4 tag(s) WAF\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022kube-controller\u0022, \u0022service_banner\u0022: \u0022kube-controller-manager\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002210257\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_ua_disclosed_scanner\u0022, \u0022net_web_probe\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:10257","http_user_agent":"Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks.com\/r\/1\/Cortex-Xpanse\/Scanning-activity","http_referer":null,"tags":"[\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_ua_disclosed_scanner\u0022, \u0022net_web_probe\u0022]","anomalies":"[]","severity":3,"bytes_in":219},{"id":8517287,"ip":"198.235.24.240","ts":"2026-06-07 18:25:15.000000","proto":"tcp","src_port":57530,"dst_port":10004,"service":"tls","classification":"port_10004_tcp","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u002216ee84a07b55074cb2751329bf1c8811\u0022, \u0022tls_sni\u0022: null, \u0022tls_weak_cipher\u0022: true, \u0022tls_weak_cipher_count\u0022: 5, \u0022bytes_in\u0022: 110, \u0022payload_entropy\u0022: 4.269606220838881, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 10004, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 38.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 43.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 6, \u0022risk_granularity\u0022: 4.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 38.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 40, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00229f673d21d702bcff323cb8235916bef90f813669\u0022, \u0022event_fingerprint\u0022: \u002287e38a33bab9e83257c904778d56b36280ef5bba\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_10004_tcp \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.57, \u0022classification_confidence\u0022: 0.57, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0348\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0348\u0022], \u0022matched_patterns\u0022: [\u0022pat-0348\u0022, \u0022pat-0868\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022RDP TPKT header\u0022, \u0022ET H.323 setup\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0348\u0022, \u0022pat-0868\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 38.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 40, \u0022correlation_boost\u0022: 8}, \u0022named_classification_skipped\u0022: true, \u0022named_candidate\u0022: \u0022rdp_probe\u0022, \u0022service_name\u0022: \u0022tls\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022ja3\u0022: \u002216ee84a07b55074cb2751329bf1c8811\u0022, \u0022payload_hash\u0022: \u00224ad5dce8143f2bcf1242885cff6e93f8\u0022, \u0022path_pattern_hash\u0022: \u00228ff328f88430fa1b70a4a3792d4ec9a2\u0022, \u0022ja4\u0022: \u0022011b865e5f91ae5e1836c88110724dcb\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 6, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022}, \u0022tls_ja3\u0022: \u0022771,47-10-19-57-4-255,13,,\u0022, \u0022tls_ja4_hash\u0022: \u0022011b865e5f91ae5e1836c88110724dcb\u0022, \u0022tls_ja4\u0022: \u0022t13d0106_3fdba35f04dc_d03502c43d74\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 6, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022, \u0022target_context\u0022: {\u0022dst_port\u0022: 10004, \u0022service\u0022: \u0022tls\u0022, \u0022service_name\u0022: \u0022tls\u0022, \u0022risk_score\u0022: 40}, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0000\\u0000i\\u0001\\u0000\\u0000e\\u0003\\u0003U\\u001c\ufffd\ufffdrandom1random2random3random4\\u0000\\u0000\\f\\u0000\/\\u0000\\n\\u0000\\u0013\\u00009\\u0000\\u0004\\u0000\ufffd\\u0001\\u0000\\u00000\\u0000\\r\\u0000,\\u0000*\\u0000\\u0001\\u0000\\u0003\\u0000\\u0002\\u0006\\u0001\\u0006\\u0003\\u0006\\u0002\\u0002\\u0001\\u0002\\u0003\\u0002\\u0002\\u0003\\u0001\\u0003\\u0003\\u0003\\u0002\\u0004\\u0001\\u0004\\u0003\\u0004\\u0002\\u0001\\u0001\\u0001\\u0003\\u0001\\u0002\\u0005\\u0001\\u0005\\u0003\\u0005\\u0002\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0000\\u0000i\\u0001\\u0000\\u0000e\\u0003\\u0003U\\u001c\ufffd\ufffdrandom1random2random3random4\\u0000\\u0000\\f\\u0000\/\\u0000\\n\\u0000\\u0013\\u00009\\u0000\\u0004\\u0000\ufffd\\u0001\\u0000\\u00000\\u0000\\r\\u0000,\\u0000*\\u0000\\u0001\\u0000\\u0003\\u0000\\u0002\\u0006\\u0001\\u0006\\u0003\\u0006\\u0002\\u0002\\u0001\\u0002\\u0003\\u0002\\u0002\\u0003\\u0001\\u0003\\u0003\\u0003\\u0002\\u0004\\u0001\\u0004\\u0003\\u0004\\u0002\\u0001\\u0001\\u0001\\u0003\\u0001\\u0002\\u0005\\u0001\\u0005\\u0003\\u0005\\u0002\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0000\\u0000i\\u0001\\u0000\\u0000e\\u0003\\u0003U\\u001c\ufffd\ufffdrandom1random2random3random4\\u0000\\u0000\\f\\u0000\/\\u0000\\n\\u0000\\u0013\\u00009\\u0000\\u0004\\u0000\ufffd\\u0001\\u0000\\u00000\\u0000\\r\\u0000,\\u0000*\\u0000\\u0001\\u0000\\u0003\\u0000\\u0002\\u0006\\u0001\\u0006\\u0003\\u0006\\u0002\\u0002\\u0001\\u0002\\u0003\\u0002\\u0002\\u0003\\u0001\\u0003\\u0003\\u0003\\u0002\\u0004\\u0001\\u0004\\u0003\\u0004\\u0002\\u0001\\u0001\\u0001\\u0003\\u0001\\u0002\\u0005\\u0001\\u0005\\u0003\\u0005\\u0002\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_10004_tcp \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022f8e1d39b51576c41c7621c4da1de42783a87d23c\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0000\\u0000i\\u0001\\u0000\\u0000e\\u0003\\u0003U\\u001c\ufffd\ufffdrandom1random2random3random4\\u0000\\u0000\\f\\u0000\/\\u0000\\n\\u0000\\u0013\\u00009\\u0000\\u0004\\u0000\ufffd\\u0001\\u0000\\u00000\\u0000\\r\\u0000,\\u0000*\\u0000\\u0001\\u0000\\u0003\\u0000\\u0002\\u0006\\u0001\\u0006\\u0003\\u0006\\u0002\\u0002\\u0001\\u0002\\u0003\\u0002\\u0002\\u0003\\u0001\\u0003\\u0003\\u0003\\u0002\\u0004\\u0001\\u0004\\u0003\\u0004\\u0002\\u0001\\u0001\\u0001\\u0003\\u0001\\u0002\\u0005\\u0001\\u0005\\u0003\\u0005\\u0002\u0022, \u0022tls_ja3\u0022: \u002216ee84a07b55074cb2751329bf1c8811\u0022, \u0022tls_ja4\u0022: \u0022011b865e5f91ae5e1836c88110724dcb\u0022, \u0022port\u0022: 10004, \u0022service\u0022: \u0022tls\u0022, \u0022service_label_fr\u0022: \u0022TLS\u0022}, \u0022evidence_snippet\u0022: \u0022ieU\ufffd\ufffdrandom1random2random3random4\/\\n9\ufffd0\\r,*\u0022, \u0022attack_vector\u0022: \u0022port 10004 tcp \u00b7 via TLS:10004 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002210004 \u00b7 TLS\u0022, \u0022emulator_service\u0022: \u0022tls\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9 \u00b7 Classification nomm\u00e9e non retenue \u2014 preuves insuffisantes\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab port_10004_tcp \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab port_10004_tcp \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 40\/100 (Moyen) \u2014 MITRE TA0007 \u2014 confiance 57 % \u2014 via TLS \u2014 multi-protocole (2 protocoles \u00b7 5 min)\u0022, \u0022confidence_pct\u0022: 57, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 38.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 40, \u0022correlation_boost\u0022: 8}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 40, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022tls\u0022, \u0022service_label_fr\u0022: \u0022TLS\u0022, \u0022dst_port\u0022: 10004, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022pat-0348\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0348\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-tls\u0022, \u0022correlation_flags\u0022: [\u0022multi_protocol_correlation\u0022], \u0022correlation_flags_labels_fr\u0022: [\u0022Multi-protocole corr\u00e9l\u00e9 (5 min)\u0022], \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Corr\u00e9lation +8\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0000\\u0000i\\u0001\\u0000\\u0000e\\u0003\\u0003U\\u001c\ufffd\ufffdrandom1random2random3random4\\u0000\\u0000\\f\\u0000\/\\u0000\\n\\u0000\\u0013\\u00009\\u0000\\u0004\\u0000\ufffd\\u0001\\u0000\\u00000\\u0000\\r\\u0000,\\u0000*\\u0000\\u0001\\u0000\\u0003\\u0000\\u0002\\u0006\\u0001\\u0006\\u0003\\u0006\\u0002\\u0002\\u0001\\u0002\\u0003\\u0002\\u0002\\u0003\\u0001\\u0003\\u0003\\u0003\\u0002\\u0004\\u0001\\u0004\\u0003\\u0004\\u0002\\u0001\\u0001\\u0001\\u0003\\u0001\\u0002\\u0005\\u0001\\u0005\\u0003\\u0005\\u0002\u0022, \u0022tls_ja3\u0022: \u002216ee84a07b55074cb2751329bf1c8811\u0022, \u0022tls_ja4\u0022: \u0022011b865e5f91ae5e1836c88110724dcb\u0022, \u0022port\u0022: 10004, \u0022service\u0022: \u0022tls\u0022, \u0022service_label_fr\u0022: \u0022TLS\u0022}, \u0022attack_vector\u0022: \u0022port 10004 tcp \u00b7 via TLS:10004 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022ieU\ufffd\ufffdrandom1random2random3random4\/\\n9\ufffd0\\r,*\u0022, \u0022target_port_label\u0022: \u002210004 \u00b7 TLS\u0022, \u0022emulator_service\u0022: \u0022tls\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9 \u00b7 Classification nomm\u00e9e non retenue \u2014 preuves insuffisantes\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 57 % \u2014 Score WAF 8 \u00b7 Bonus corr\u00e9lation +8\u0022}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022tls\u0022, \u0022service_banner\u0022: \u0022honeypot-tls\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002210004\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022multi_protocol_correlation\u0022: true, \u0022multi_protocol_count\u0022: 2, \u0022multi_protocol_sample\u0022: [\u0022port:10004\u0022, \u0022tls\u0022], \u0022multi_protocol_window_s\u0022: 300, \u0022behavior_alerts\u0022: [\u0022multi_protocol_correlation\u0022], \u0022correlation_confidence_boost\u0022: 8, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":"16ee84a07b55074cb2751329bf1c8811","tls_ja3":"771,47-10-19-57-4-255,13,,","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022]","anomalies":"[]","severity":4,"bytes_in":110},{"id":8517288,"ip":"198.235.24.240","ts":"2026-06-07 18:25:15.000000","proto":"tcp","src_port":57546,"dst_port":10004,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022004556e859f3c26c5d19746b3a957c74\u0022, \u0022tls_sni\u0022: null, \u0022tls_weak_cipher\u0022: true, \u0022tls_weak_cipher_count\u0022: 8, \u0022bytes_in\u0022: 517, \u0022payload_entropy\u0022: 3.9752153491498503, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 10004, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 43.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 6, \u0022risk_granularity\u0022: 4.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00229f673d21d702bcff323cb8235916bef90f813669\u0022, \u0022event_fingerprint\u0022: \u0022d4a1415ad8e9029009ffe478338a3fd823aec319\u0022, \u0022classification_confidence\u0022: 0.58, \u0022confidence\u0022: 0.58, \u0022precision_signals\u0022: [\u0022pat-0554\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab tls_probe \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 35, \u0022correlation_boost\u0022: 8}, \u0022service_name\u0022: \u0022tls\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022ja3\u0022: \u0022004556e859f3c26c5d19746b3a957c74\u0022, \u0022payload_hash\u0022: \u0022486b4cefd5df2a8ebc28fc24906d9355\u0022, \u0022path_pattern_hash\u0022: \u00228792d2cfdc5028123bfb8f159de8656c\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 10004, \u0022service\u0022: \u0022tls\u0022, \u0022service_name\u0022: \u0022tls\u0022, \u0022risk_score\u0022: 35}, \u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0002\\u0000\\u0001\\u0000\\u0001\ufffd\\u0003\\u0003\ufffd\ufffd\ufffd\ufffd\ufffd0c\\f\ufffd\ufffdJ\ufffd\ufffdoCVb\\u0002\\u0002\/M\u0027x\ufffdrH2Z{\ufffd{\ufffd \\u0006]\ufffd?\\u000f\ufffd\ufffd\\u0012\ufffd\\u001dv\ufffd\ufffd\ufffd\u0460\ufffd8\\u000eH_\ufffd!(\ufffd\ufffdD\\u0012G\ufffd\ufffd*\\u0000\u003E\\u0013\\u0002\\u0013\\u0003\\u0013\\u0001\ufffd,\ufffd0\\u0000\ufffd\u0329\u0328\u032a\ufffd+\ufffd\/\\u0000\ufffd\ufffd$\ufffd(\\u0000k\ufffd#\ufffd\u0027\\u0000g\ufffd\\n\ufffd\\u0014\\u00009\ufffd\\t\ufffd\\u0013\\u00003\\u0000\ufffd\u0022, \u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0002\\u0000\\u0001\\u0000\\u0001\ufffd\\u0003\\u0003\ufffd\ufffd\ufffd\ufffd\ufffd0c\\f\ufffd\ufffdJ\ufffd\ufffdoCVb\\u0002\\u0002\/M\u0027x\ufffdrH2Z{\ufffd{\ufffd \\u0006]\ufffd?\\u000f\ufffd\ufffd\\u0012\ufffd\\u001dv\ufffd\ufffd\ufffd\u0460\ufffd8\\u000eH_\ufffd!(\ufffd\ufffdD\\u0012G\ufffd\ufffd*\\u0000\u003E\\u0013\\u0002\\u0013\\u0003\\u0013\\u0001\ufffd,\ufffd0\\u0000\ufffd\u0329\u0328\u032a\ufffd+\ufffd\/\\u0000\ufffd\ufffd$\ufffd(\\u0000k\ufffd#\ufffd\u0027\\u0000g\ufffd\\n\ufffd\\u0014\\u00009\ufffd\\t\ufffd\\u0013\\u00003\\u0000\ufffd\\u0000\ufffd\\u0000=\\u0000\u003C\\u00005\\u0000\/\\u0000\ufffd\\u0001\\u0000\\u0001u\\u0000\\u000b\\u0000\\u0004\\u0003\\u0000\\u0001\\u0002\\u0000\\n\\u0000\\f\\u0000\\n\\u0000\\u001d\\u0000\\u0017\\u0000\\u001e\\u0000\\u0019\\u0000\\u0018\\u0000#\\u0000\\u0000\\u0000\\u0016\\u0000\\u0000\\u0000\\u0017\\u0000\\u0000\\u0000\\r\\u00000\\u0000.\\u0004\\u0003\\u0005\\u0003\\u0006\\u0003\\b\\u0007\\b\\b\\b\\t\\b\\n\\b\\u000b\\b\\u0004\\b\\u0005\\b\\u0006\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\\u0003\\u0003\\u0002\\u0003\\u0003\\u0001\\u0002\\u0001\\u0003\\u0002\\u0002\\u0002\\u0004\\u0002\\u0005\\u0002\\u0006\\u0002\\u0000+\\u0000\\t\\b\\u0003\\u0004\\u0003\\u0003\\u0003\\u0002\\u0003\\u0001\\u0000-\\u0000\\u0002\\u0001\\u0001\\u00003\\u0000\u0026\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0002\\u0000\\u0001\\u0000\\u0001\ufffd\\u0003\\u0003\ufffd\ufffd\ufffd\ufffd\ufffd0c\\f\ufffd\ufffdJ\ufffd\ufffdoCVb\\u0002\\u0002\/M\u0027x\ufffdrH2Z{\ufffd{\ufffd \\u0006]\ufffd?\\u000f\ufffd\ufffd\\u0012\ufffd\\u001dv\ufffd\ufffd\ufffd\u0460\ufffd8\\u000eH_\ufffd!(\ufffd\ufffdD\\u0012G\ufffd\ufffd*\\u0000\u003E\\u0013\\u0002\\u0013\\u0003\\u0013\\u0001\ufffd,\ufffd0\\u0000\ufffd\u0329\u0328\u032a\ufffd+\ufffd\/\\u0000\ufffd\ufffd$\ufffd(\\u0000k\ufffd#\ufffd\u0027\\u0000g\ufffd\\n\ufffd\\u0014\\u00009\ufffd\\t\ufffd\\u0013\\u00003\\u0000\ufffd\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0002\\u0000\\u0001\\u0000\\u0001\ufffd\\u0003\\u0003\ufffd\ufffd\ufffd\ufffd\ufffd0c\\f\ufffd\ufffdJ\ufffd\ufffdoCVb\\u0002\\u0002\/M\u0027x\ufffdrH2Z{\ufffd{\ufffd \\u0006]\ufffd?\\u000f\ufffd\ufffd\\u0012\ufffd\\u001dv\ufffd\ufffd\ufffd\u0460\ufffd8\\u000eH_\ufffd!(\ufffd\ufffdD\\u0012G\ufffd\ufffd*\\u0000\u003E\\u0013\\u0002\\u0013\\u0003\\u0013\\u0001\ufffd,\ufffd0\\u0000\ufffd\u0329\u0328\u032a\ufffd+\ufffd\/\\u0000\ufffd\ufffd$\ufffd(\\u0000k\ufffd#\ufffd\u0027\\u0000g\ufffd\\n\ufffd\\u0014\\u00009\ufffd\\t\ufffd\\u0013\\u00003\\u0000\ufffd\\u0000\ufffd\\u0000=\\u0000\u003C\\u00005\\u0000\/\\u0000\ufffd\\u0001\\u0000\\u0001u\\u0000\\u000b\\u0000\\u0004\\u0003\\u0000\\u0001\\u0002\\u0000\\n\\u0000\\f\\u0000\\n\\u0000\\u001d\\u0000\\u0017\\u0000\\u001e\\u0000\\u0019\\u0000\\u0018\\u0000#\\u0000\\u0000\\u0000\\u0016\\u0000\\u0000\\u0000\\u0017\\u0000\\u0000\\u0000\\r\\u00000\\u0000.\\u0004\\u0003\\u0005\\u0003\\u0006\\u0003\\b\\u0007\\b\\b\\b\\t\\b\\n\\b\\u000b\\b\\u0004\\b\\u0005\\b\\u0006\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\\u0003\\u0003\\u0002\\u0003\\u0003\\u0001\\u0002\\u0001\\u0003\\u0002\\u0002\\u0002\\u0004\\u0002\\u0005\\u0002\\u0006\\u0002\\u0000+\\u0000\\t\\b\\u0003\\u0004\\u0003\\u0003\\u0003\\u0002\\u0003\\u0001\\u0000-\\u0000\\u0002\\u0001\\u0001\\u00003\\u0000\u0026\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0002\\u0000\\u0001\\u0000\\u0001\ufffd\\u0003\\u0003\ufffd\ufffd\ufffd\ufffd\ufffd0c\\f\ufffd\ufffdJ\ufffd\ufffdoCVb\\u0002\\u0002\/M\u0027x\ufffdrH2Z{\ufffd{\ufffd \\u0006]\ufffd?\\u000f\ufffd\ufffd\\u0012\ufffd\\u001dv\ufffd\ufffd\ufffd\u0460\ufffd8\\u000eH_\ufffd!(\ufffd\ufffdD\\u0012G\ufffd\ufffd*\\u0000\u003E\\u0013\\u0002\\u0013\\u0003\\u0013\\u0001\ufffd,\ufffd0\\u0000\ufffd\u0329\u0328\u032a\ufffd+\ufffd\/\\u0000\ufffd\ufffd$\ufffd(\\u0000k\ufffd#\ufffd\u0027\\u0000g\ufffd\\n\ufffd\\u0014\\u00009\ufffd\\t\ufffd\\u0013\\u00003\\u0000\ufffd\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab tls_probe \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002247955427347a90adb3f2753db96b6357bbe7360a\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0002\\u0000\\u0001\\u0000\\u0001\ufffd\\u0003\\u0003\ufffd\ufffd\ufffd\ufffd\ufffd0c\\f\ufffd\ufffdJ\ufffd\ufffdoCVb\\u0002\\u0002\/M\u0027x\ufffdrH2Z{\ufffd{\ufffd \\u0006]\ufffd?\\u000f\ufffd\ufffd\\u0012\ufffd\\u001dv\ufffd\ufffd\ufffd\u0460\ufffd8\\u000eH_\ufffd!(\ufffd\ufffdD\\u0012G\ufffd\ufffd*\\u0000\u003E\\u0013\\u0002\\u0013\\u0003\\u0013\\u0001\ufffd,\ufffd0\\u0000\ufffd\u0329\u0328\u032a\ufffd+\ufffd\/\\u0000\ufffd\ufffd$\ufffd(\\u0000k\ufffd#\ufffd\u0027\\u0000g\ufffd\\n\ufffd\\u0014\\u00009\ufffd\\t\ufffd\\u0013\\u00003\\u0000\ufffd\u0022, \u0022tls_ja3\u0022: \u0022004556e859f3c26c5d19746b3a957c74\u0022, \u0022port\u0022: 10004, \u0022service\u0022: \u0022tls\u0022, \u0022service_label_fr\u0022: \u0022TLS\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd0c\ufffd\ufffdJ\ufffd\ufffdoCVb\/M\u0027x\ufffdrH2Z{\ufffd{\ufffd ]\ufffd?\ufffd\ufffd\ufffdv\ufffd\ufffd\ufffd\u0460\ufffd8H_\ufffd!(\ufffd\ufffdDG\ufffd\ufffd*\u003E\ufffd,\ufffd0\ufffd\u0329\u0328\u032a\ufffd+\ufffd\/\ufffd\ufffd$\ufffd(k\ufffd#\ufffd\u0027g\ufffd\\n\ufffd9\ufffd\\t\ufffd3\ufffd\u0022, \u0022attack_vector\u0022: \u0022tls probe \u00b7 via TLS:10004 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002210004 \u00b7 TLS\u0022, \u0022emulator_service\u0022: \u0022tls\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab tls_probe \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab tls_probe \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 35\/100 (Faible) \u2014 MITRE TA0007 \u2014 confiance 58 % \u2014 via TLS \u2014 multi-protocole (2 protocoles \u00b7 5 min)\u0022, \u0022confidence_pct\u0022: 58, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 43.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 35, \u0022correlation_boost\u0022: 8}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 35, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022tls\u0022, \u0022service_label_fr\u0022: \u0022TLS\u0022, \u0022dst_port\u0022: 10004, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022pat-0554\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0554\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-tls\u0022, \u0022correlation_flags\u0022: [\u0022multi_protocol_correlation\u0022], \u0022correlation_flags_labels_fr\u0022: [\u0022Multi-protocole corr\u00e9l\u00e9 (5 min)\u0022], \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Corr\u00e9lation +8\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0002\\u0000\\u0001\\u0000\\u0001\ufffd\\u0003\\u0003\ufffd\ufffd\ufffd\ufffd\ufffd0c\\f\ufffd\ufffdJ\ufffd\ufffdoCVb\\u0002\\u0002\/M\u0027x\ufffdrH2Z{\ufffd{\ufffd \\u0006]\ufffd?\\u000f\ufffd\ufffd\\u0012\ufffd\\u001dv\ufffd\ufffd\ufffd\u0460\ufffd8\\u000eH_\ufffd!(\ufffd\ufffdD\\u0012G\ufffd\ufffd*\\u0000\u003E\\u0013\\u0002\\u0013\\u0003\\u0013\\u0001\ufffd,\ufffd0\\u0000\ufffd\u0329\u0328\u032a\ufffd+\ufffd\/\\u0000\ufffd\ufffd$\ufffd(\\u0000k\ufffd#\ufffd\u0027\\u0000g\ufffd\\n\ufffd\\u0014\\u00009\ufffd\\t\ufffd\\u0013\\u00003\\u0000\ufffd\u0022, \u0022tls_ja3\u0022: \u0022004556e859f3c26c5d19746b3a957c74\u0022, \u0022port\u0022: 10004, \u0022service\u0022: \u0022tls\u0022, \u0022service_label_fr\u0022: \u0022TLS\u0022}, \u0022attack_vector\u0022: \u0022tls probe \u00b7 via TLS:10004 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd0c\ufffd\ufffdJ\ufffd\ufffdoCVb\/M\u0027x\ufffdrH2Z{\ufffd{\ufffd ]\ufffd?\ufffd\ufffd\ufffdv\ufffd\ufffd\ufffd\u0460\ufffd8H_\ufffd!(\ufffd\ufffdDG\ufffd\ufffd*\u003E\ufffd,\ufffd0\ufffd\u0329\u0328\u032a\ufffd+\ufffd\/\ufffd\ufffd$\ufffd(k\ufffd#\ufffd\u0027g\ufffd\\n\ufffd9\ufffd\\t\ufffd3\ufffd\u0022, \u0022target_port_label\u0022: \u002210004 \u00b7 TLS\u0022, \u0022emulator_service\u0022: \u0022tls\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 58 % \u2014 Score WAF 8 \u00b7 Bonus corr\u00e9lation +8\u0022}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022tls\u0022, \u0022service_banner\u0022: \u0022honeypot-tls\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002210004\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022multi_protocol_correlation\u0022: true, \u0022multi_protocol_count\u0022: 2, \u0022multi_protocol_sample\u0022: [\u0022port:10004\u0022, \u0022tls\u0022], \u0022multi_protocol_window_s\u0022: 300, \u0022behavior_alerts\u0022: [\u0022multi_protocol_correlation\u0022], \u0022correlation_confidence_boost\u0022: 8, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":"004556e859f3c26c5d19746b3a957c74","tls_ja3":"771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47-255,11-10-35-22-23-13-43-45-51-21,29-23-30-25-24,0-1-2","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022]","anomalies":"[]","severity":4,"bytes_in":517},{"id":8517286,"ip":"198.235.24.240","ts":"2026-06-07 18:25:12.000000","proto":"tcp","src_port":57524,"dst_port":10004,"service":null,"classification":"port_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 0, \u0022payload_entropy\u0022: 0.0, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 10004, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 48.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 0.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.5, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 48.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 0.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 44, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022cf5e2d8903c20a2715fff95f2c2d222b806eca86\u0022, \u0022event_fingerprint\u0022: \u00221838f59485d47f899577198441c4be74341fc0a8\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022INT-single-port\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab port_probe \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 48.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 0.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 44}, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022path_pattern_hash\u0022: \u002249ebffbc8eed300cf9429db1ba4cf66d\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 10004, \u0022risk_score\u0022: 44}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022706283f66f3ecb2cc2d01b8950df009acdb1128a\u0022, \u0022protocol_details\u0022: {\u0022port\u0022: 10004}, \u0022attack_vector\u0022: \u0022Sonde port \u00b7 port 10004 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002210004\u0022, \u0022confidence_reason\u0022: \u0022Confiance mod\u00e9r\u00e9e (50 %) \u2014 signal principal unique\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab port_probe \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab port_probe \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 44\/100 (Moyen) \u2014 MITRE TA0007 \u2014 confiance 50 %\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 48.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 0.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 44}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 44, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: null, \u0022service_label_fr\u0022: null, \u0022dst_port\u0022: 10004, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022INT-single-port\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022Single Port\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022port\u0022: 10004}, \u0022attack_vector\u0022: \u0022Sonde port \u00b7 port 10004 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: null, \u0022target_port_label\u0022: \u002210004\u0022, \u0022emulator_service\u0022: null, \u0022confidence_reason\u0022: \u0022Confiance mod\u00e9r\u00e9e (50 %) \u2014 signal principal unique\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022generic\u0022, \u0022service_banner\u0022: \u0022honeypot\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002210004\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":0,"bytes_in":0},{"id":8511784,"ip":"198.235.24.240","ts":"2026-06-07 16:55:56.000000","proto":"tcp","src_port":58236,"dst_port":3389,"service":"rdp","classification":"rdp_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022030000130ed000001234000200080000000000\u0022, \u0022emulator_response_len\u0022: 19, \u0022bytes_in\u0022: 287, \u0022payload_entropy\u0022: 5.91119938279526, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022rdp\u0022, \u0022app_proto\u0022: \u0022rdp\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 3389, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 52.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 52.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 50, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002240bf2c34d73676fee23426938806aaa527b96fcb\u0022, \u0022event_fingerprint\u0022: \u0022ad5bc6c1132c10ce0e88d551a1bd2cf31dc3757e\u0022, \u0022classification_reason\u0022: \u0022N\u00e9gociation protocole RDP \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 116, \u0022precision_signals\u0022: [\u0022pat-0347\u0022, \u0022pat-0348\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0347\u0022, \u0022pat-0348\u0022], \u0022matched_patterns\u0022: [\u0022pat-0347\u0022, \u0022pat-0348\u0022, \u0022pat-0369\u0022, \u0022pat-0868\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022RDP NTLM hash\u0022, \u0022RDP TPKT header\u0022, \u0022PostgreSQL startup\u0022, \u0022ET H.323 setup\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022SOCKS5 greeting\u0022, \u0022SIP TLS ClientHello\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0347\u0022, \u0022pat-0348\u0022, \u0022pat-0369\u0022, \u0022pat-0868\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 52.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 50}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022rdp\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002207408e4ffdf30dbd4bc63d94824647fe\u0022, \u0022path_pattern_hash\u0022: \u00225dd788b551ee7afb63321e74cfc538f6\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 3389, \u0022service\u0022: \u0022rdp\u0022, \u0022service_name\u0022: \u0022rdp\u0022, \u0022risk_score\u0022: 50}, \u0022payload_preview\u0022: \u0022\\u0003\\u0000\\u0000,\u0027\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000Cookie: mstshash=tkMYsa\\r\\n\\u0001\\u0000\\b\\u0000\\u0001\\u0000\\u0000\\u0000\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003y\ufffdIp\ufffd\ufffd\\u000f\ufffd\ufffd\ufffd\ufffd\ufffd\\t\ufffd;\ufffd\u0763P\ufffd\ufffdL\u003C\ufffd\ufffd\ufffd\ufffd\\u001ac\\n\ufffd\\u000e \ufffd\ufffd\\u0012\u045d\\u001c\\u0005\ufffd\\u0000v\ufffdn\\u0017\ufffd\ufffdf\ufffd\ufffd\\u001f \ufffd\ufffd\ufffd=pg\u003C\u0026\\\\\ufffd\ufffd.\\u0000\u0026\ufffd+\ufffd\/\ufffd,\u0022, \u0022request_sample\u0022: \u0022\\u0003\\u0000\\u0000,\u0027\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000Cookie: mstshash=tkMYsa\\r\\n\\u0001\\u0000\\b\\u0000\\u0001\\u0000\\u0000\\u0000\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003y\ufffdIp\ufffd\ufffd\\u000f\ufffd\ufffd\ufffd\ufffd\ufffd\\t\ufffd;\ufffd\u0763P\ufffd\ufffdL\u003C\ufffd\ufffd\ufffd\ufffd\\u001ac\\n\ufffd\\u000e \ufffd\ufffd\\u0012\u045d\\u001c\\u0005\ufffd\\u0000v\ufffdn\\u0017\ufffd\ufffdf\ufffd\ufffd\\u001f \ufffd\ufffd\ufffd=pg\u003C\u0026\\\\\ufffd\ufffd.\\u0000\u0026\ufffd+\ufffd\/\ufffd,\ufffd0\u0329\u0328\ufffd\\t\ufffd\\u0013\ufffd\\n\ufffd\\u0014\\u0000\ufffd\\u0000\ufffd\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0013\\u0001\\u0013\\u0002\\u0013\\u0003\\u0001\\u0000\\u0000{\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\n\\u0000\\b\\u0000\\u001d\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u001a\\u0000\\u0018\\b\\u0004\\u0004\\u0003\\b\\u0007\\b\\u0005\\b\\u0006\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\\u0005\\u0003\\u0006\\u0003\\u0002\\u0001\\u0002\\u0003\ufffd\\u0001\\u0000\\u0001\\u0000\\u0000\\u0012\\u0000\\u0000\\u0000+\\u0000\\t\\b\\u0003\\u0004\\u0003\\u0003\\u0003\\u0002\\u0003\\u0001\\u00003\\u0000\u0026\\u0000$\\u0000\\u001d\\u0000 \ufffd\u0022, \u0022payload_snippet\u0022: \u0022\\u0003\\u0000\\u0000,\u0027\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000Cookie: mstshash=tkMYsa\\r\\n\\u0001\\u0000\\b\\u0000\\u0001\\u0000\\u0000\\u0000\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003y\ufffdIp\ufffd\ufffd\\u000f\ufffd\ufffd\ufffd\ufffd\ufffd\\t\ufffd;\ufffd\u0763P\ufffd\ufffdL\u003C\ufffd\ufffd\ufffd\ufffd\\u001ac\\n\ufffd\\u000e \ufffd\ufffd\\u0012\u045d\\u001c\\u0005\ufffd\\u0000v\ufffdn\\u0017\ufffd\ufffdf\ufffd\ufffd\\u001f \ufffd\ufffd\ufffd=pg\u003C\u0026\\\\\ufffd\ufffd.\\u0000\u0026\ufffd+\ufffd\/\ufffd,\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0003\\u0000\\u0000,\u0027\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000Cookie: mstshash=tkMYsa\\r\\n\\u0001\\u0000\\b\\u0000\\u0001\\u0000\\u0000\\u0000\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003y\ufffdIp\ufffd\ufffd\\u000f\ufffd\ufffd\ufffd\ufffd\ufffd\\t\ufffd;\ufffd\u0763P\ufffd\ufffdL\u003C\ufffd\ufffd\ufffd\ufffd\\u001ac\\n\ufffd\\u000e \ufffd\ufffd\\u0012\u045d\\u001c\\u0005\ufffd\\u0000v\ufffdn\\u0017\ufffd\ufffdf\ufffd\ufffd\\u001f \ufffd\ufffd\ufffd=pg\u003C\u0026\\\\\ufffd\ufffd.\\u0000\u0026\ufffd+\ufffd\/\ufffd,\ufffd0\u0329\u0328\ufffd\\t\ufffd\\u0013\ufffd\\n\ufffd\\u0014\\u0000\ufffd\\u0000\ufffd\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0013\\u0001\\u0013\\u0002\\u0013\\u0003\\u0001\\u0000\\u0000{\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\n\\u0000\\b\\u0000\\u001d\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\u001a\\u0000\\u0018\\b\\u0004\\u0004\\u0003\\b\\u0007\\b\\u0005\\b\\u0006\\u0004\\u0001\\u0005\\u0001\\u0006\\u0001\\u0005\\u0003\\u0006\\u0003\\u0002\\u0001\\u0002\\u0003\ufffd\\u0001\\u0000\\u0001\\u0000\\u0000\\u0012\\u0000\\u0000\\u0000+\\u0000\\t\\b\\u0003\\u0004\\u0003\\u0003\\u0003\\u0002\\u0003\\u0001\\u00003\\u0000\u0026\\u0000$\\u0000\\u001d\\u0000 \ufffd\u0022, \u0022payload_snippet\u0022: \u0022\\u0003\\u0000\\u0000,\u0027\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000Cookie: mstshash=tkMYsa\\r\\n\\u0001\\u0000\\b\\u0000\\u0001\\u0000\\u0000\\u0000\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003y\ufffdIp\ufffd\ufffd\\u000f\ufffd\ufffd\ufffd\ufffd\ufffd\\t\ufffd;\ufffd\u0763P\ufffd\ufffdL\u003C\ufffd\ufffd\ufffd\ufffd\\u001ac\\n\ufffd\\u000e \ufffd\ufffd\\u0012\u045d\\u001c\\u0005\ufffd\\u0000v\ufffdn\\u0017\ufffd\ufffdf\ufffd\ufffd\\u001f \ufffd\ufffd\ufffd=pg\u003C\u0026\\\\\ufffd\ufffd.\\u0000\u0026\ufffd+\ufffd\/\ufffd,\u0022, \u0022classification_reason\u0022: \u0022N\u00e9gociation protocole RDP \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022investigate\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00223a949453bd51b4b62dc12ee8d1808a36c78f437f\u0022, \u0022protocol_details\u0022: {\u0022port\u0022: 3389, \u0022service\u0022: \u0022rdp\u0022, \u0022service_label_fr\u0022: \u0022RDP\u0022}, \u0022evidence_snippet\u0022: \u0022,\u0027\ufffdCookie: mstshash=tkMYsa\\r\\n\ufffd\ufffdy\ufffdIp\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\t\ufffd;\ufffd\u0763P\ufffd\ufffdL\u003C\ufffd\ufffd\ufffd\ufffdc\\n\ufffd \ufffd\ufffd\u045d\ufffdv\ufffdn\ufffd\ufffdf\ufffd\ufffd \ufffd\ufffd\ufffd=pg\u003C\u0026\\\\\ufffd\ufffd.\u0026\ufffd+\ufffd\/\ufffd,\u0022, \u0022attack_vector\u0022: \u0022rdp probe \u00b7 via RDP:3389 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00223389 \u00b7 RDP\u0022, \u0022emulator_service\u0022: \u0022rdp\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022N\u00e9gociation protocole RDP \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022N\u00e9gociation protocole RDP \u00b7 confiance 100%\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 52.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 50}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 50, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022rdp\u0022, \u0022service_label_fr\u0022: \u0022RDP\u0022, \u0022dst_port\u0022: 3389, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0347\u0022, \u0022pat-0348\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0347\u0022, \u0022pat-0348\u0022], \u0022recommended_action\u0022: \u0022investigate\u0022, \u0022recommended_action_label\u0022: \u0022Investiguer\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022Windows RDP\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022port\u0022: 3389, \u0022service\u0022: \u0022rdp\u0022, \u0022service_label_fr\u0022: \u0022RDP\u0022}, \u0022attack_vector\u0022: \u0022rdp probe \u00b7 via RDP:3389 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022,\u0027\ufffdCookie: mstshash=tkMYsa\\r\\n\ufffd\ufffdy\ufffdIp\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\\t\ufffd;\ufffd\u0763P\ufffd\ufffdL\u003C\ufffd\ufffd\ufffd\ufffdc\\n\ufffd \ufffd\ufffd\u045d\ufffdv\ufffdn\ufffd\ufffdf\ufffd\ufffd \ufffd\ufffd\ufffd=pg\u003C\u0026\\\\\ufffd\ufffd.\u0026\ufffd+\ufffd\/\ufffd,\u0022, \u0022target_port_label\u0022: \u00223389 \u00b7 RDP\u0022, \u0022emulator_service\u0022: \u0022rdp\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022rdp\u0022, \u0022service_banner\u0022: \u0022Windows RDP\u0022, \u0022service_os\u0022: \u0022windows\u0022, \u0022dst_port\u0022: \u00223389\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_investigate\u0022, \u0022tags_list\u0022: [\u0022net_rdp_cookie\u0022, \u0022rdp_cookie\u0022, \u0022rdp_emulated\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022net_rdp_cookie\u0022, \u0022rdp_cookie\u0022, \u0022rdp_emulated\u0022]","anomalies":"[]","severity":6,"bytes_in":287},{"id":8511785,"ip":"198.235.24.240","ts":"2026-06-07 16:55:56.000000","proto":"tcp","src_port":58246,"dst_port":3389,"service":"rdp","classification":"postgres_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022bytes_in\u0022: 207, \u0022payload_entropy\u0022: 4.993667346191395, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022rdp\u0022, \u0022app_proto\u0022: \u0022rdp\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 3389, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 36.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 36.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 40, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00225cb9b53baf1209ea6c81c49a02d920dd293de6a4\u0022, \u0022event_fingerprint\u0022: \u0022707be242ce71f14fac23ca7fdd82d854dc2752d8\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0369\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0369\u0022], \u0022matched_patterns\u0022: [\u0022pat-0369\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022PostgreSQL startup\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022SOCKS5 greeting\u0022, \u0022SIP TLS ClientHello\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0369\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0567\u0022, \u0022pat-0578\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 36.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 40}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022rdp\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00224db470b6d0525e9112a99dbf40fb0531\u0022, \u0022path_pattern_hash\u0022: \u002280f3c71fe26f36a0a9399108643f66c5\u0022, \u0022ja3\u0022: \u0022795bc7ce13f60d61e9ac03611dd36d90\u0022, \u0022ja4\u0022: \u0022bcc542a5296d13201e694c8f5aa448d9\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 52, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022}, \u0022tls_ja3_hash\u0022: \u0022795bc7ce13f60d61e9ac03611dd36d90\u0022, \u0022tls_ja3\u0022: \u0022771,52244-52243-49199-49195-49200-49196-49169-49159-49191-49187-49171-49161-49192-49188-49172-49162-52245-158-159-103-107-51-57-156-157-5-4-60-61-47-53-49170-22-10-3-8-6-20-17-25-23-50-49160-18-19-21-56-64-102-106-162-163,5-10-11-13-65281-15,23-24-25,0\u0022, \u0022tls_ja4_hash\u0022: \u0022bcc542a5296d13201e694c8f5aa448d9\u0022, \u0022tls_ja4\u0022: \u0022t13d0152_4fb103f5e16c_40d2e578a3e2\u0022, \u0022tls_version\u0022: \u00220x0303\u0022, \u0022tls_cipher_count\u0022: 52, \u0022ja3_client_category\u0022: \u0022nmap_scanner\u0022, \u0022target_context\u0022: {\u0022dst_port\u0022: 3389, \u0022service\u0022: \u0022rdp\u0022, \u0022service_name\u0022: \u0022rdp\u0022, \u0022risk_score\u0022: 40}, \u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003e\ufffdT\ufffdc\ufffdK\ufffd\ufffd\ufffd\ufffd\u0643\ufffd\\r\ufffd\ufffd,\ufffd\ufffd\ufffd\ufffd^]o\ufffd\ufffdEB\ufffd\u003E\\u0000\\u0000h\ufffd\\u0014\ufffd\\u0013\ufffd\/\ufffd+\ufffd0\ufffd,\ufffd\\u0011\ufffd\\u0007\ufffd\u0027\ufffd#\ufffd\\u0013\ufffd\\t\ufffd(\ufffd$\ufffd\\u0014\ufffd\\n\ufffd\\u0015\\u0000\ufffd\\u0000\ufffd\\u0000g\\u0000k\\u00003\\u00009\\u0000\ufffd\\u0000\ufffd\\u0000\\u0005\\u0000\\u0004\\u0000\u003C\\u0000=\\u0000\/\\u00005\ufffd\\u0012\\u0000\\u0016\\u0000\\n\\u0000\\u0003\\u0000\\b\\u0000\\u0006\\u0000\\u0014\\u0000\\u0011\\u0000\\u0019\\u0000\\u0017\u0022, \u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003e\ufffdT\ufffdc\ufffdK\ufffd\ufffd\ufffd\ufffd\u0643\ufffd\\r\ufffd\ufffd,\ufffd\ufffd\ufffd\ufffd^]o\ufffd\ufffdEB\ufffd\u003E\\u0000\\u0000h\ufffd\\u0014\ufffd\\u0013\ufffd\/\ufffd+\ufffd0\ufffd,\ufffd\\u0011\ufffd\\u0007\ufffd\u0027\ufffd#\ufffd\\u0013\ufffd\\t\ufffd(\ufffd$\ufffd\\u0014\ufffd\\n\ufffd\\u0015\\u0000\ufffd\\u0000\ufffd\\u0000g\\u0000k\\u00003\\u00009\\u0000\ufffd\\u0000\ufffd\\u0000\\u0005\\u0000\\u0004\\u0000\u003C\\u0000=\\u0000\/\\u00005\ufffd\\u0012\\u0000\\u0016\\u0000\\n\\u0000\\u0003\\u0000\\b\\u0000\\u0006\\u0000\\u0014\\u0000\\u0011\\u0000\\u0019\\u0000\\u0017\\u00002\ufffd\\b\\u0000\\u0012\\u0000\\u0013\\u0000\\u0015\\u00008\\u0000@\\u0000f\\u0000j\\u0000\ufffd\\u0000\ufffd\\u0001\\u0000\\u00005\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\f\\u0000\\n\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0002\\u0002\ufffd\\u0001\\u0000\\u0001\\u0000\\u0000\\u000f\\u0000\\u0001\\u0001\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003e\ufffdT\ufffdc\ufffdK\ufffd\ufffd\ufffd\ufffd\u0643\ufffd\\r\ufffd\ufffd,\ufffd\ufffd\ufffd\ufffd^]o\ufffd\ufffdEB\ufffd\u003E\\u0000\\u0000h\ufffd\\u0014\ufffd\\u0013\ufffd\/\ufffd+\ufffd0\ufffd,\ufffd\\u0011\ufffd\\u0007\ufffd\u0027\ufffd#\ufffd\\u0013\ufffd\\t\ufffd(\ufffd$\ufffd\\u0014\ufffd\\n\ufffd\\u0015\\u0000\ufffd\\u0000\ufffd\\u0000g\\u0000k\\u00003\\u00009\\u0000\ufffd\\u0000\ufffd\\u0000\\u0005\\u0000\\u0004\\u0000\u003C\\u0000=\\u0000\/\\u00005\ufffd\\u0012\\u0000\\u0016\\u0000\\n\\u0000\\u0003\\u0000\\b\\u0000\\u0006\\u0000\\u0014\\u0000\\u0011\\u0000\\u0019\\u0000\\u0017\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003e\ufffdT\ufffdc\ufffdK\ufffd\ufffd\ufffd\ufffd\u0643\ufffd\\r\ufffd\ufffd,\ufffd\ufffd\ufffd\ufffd^]o\ufffd\ufffdEB\ufffd\u003E\\u0000\\u0000h\ufffd\\u0014\ufffd\\u0013\ufffd\/\ufffd+\ufffd0\ufffd,\ufffd\\u0011\ufffd\\u0007\ufffd\u0027\ufffd#\ufffd\\u0013\ufffd\\t\ufffd(\ufffd$\ufffd\\u0014\ufffd\\n\ufffd\\u0015\\u0000\ufffd\\u0000\ufffd\\u0000g\\u0000k\\u00003\\u00009\\u0000\ufffd\\u0000\ufffd\\u0000\\u0005\\u0000\\u0004\\u0000\u003C\\u0000=\\u0000\/\\u00005\ufffd\\u0012\\u0000\\u0016\\u0000\\n\\u0000\\u0003\\u0000\\b\\u0000\\u0006\\u0000\\u0014\\u0000\\u0011\\u0000\\u0019\\u0000\\u0017\\u00002\ufffd\\b\\u0000\\u0012\\u0000\\u0013\\u0000\\u0015\\u00008\\u0000@\\u0000f\\u0000j\\u0000\ufffd\\u0000\ufffd\\u0001\\u0000\\u00005\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\\u0000\\u0000\\n\\u0000\\b\\u0000\\u0006\\u0000\\u0017\\u0000\\u0018\\u0000\\u0019\\u0000\\u000b\\u0000\\u0002\\u0001\\u0000\\u0000\\r\\u0000\\f\\u0000\\n\\u0004\\u0001\\u0004\\u0003\\u0002\\u0001\\u0002\\u0003\\u0002\\u0002\ufffd\\u0001\\u0000\\u0001\\u0000\\u0000\\u000f\\u0000\\u0001\\u0001\u0022, \u0022payload_snippet\u0022: \u0022\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003e\ufffdT\ufffdc\ufffdK\ufffd\ufffd\ufffd\ufffd\u0643\ufffd\\r\ufffd\ufffd,\ufffd\ufffd\ufffd\ufffd^]o\ufffd\ufffdEB\ufffd\u003E\\u0000\\u0000h\ufffd\\u0014\ufffd\\u0013\ufffd\/\ufffd+\ufffd0\ufffd,\ufffd\\u0011\ufffd\\u0007\ufffd\u0027\ufffd#\ufffd\\u0013\ufffd\\t\ufffd(\ufffd$\ufffd\\u0014\ufffd\\n\ufffd\\u0015\\u0000\ufffd\\u0000\ufffd\\u0000g\\u0000k\\u00003\\u00009\\u0000\ufffd\\u0000\ufffd\\u0000\\u0005\\u0000\\u0004\\u0000\u003C\\u0000=\\u0000\/\\u00005\ufffd\\u0012\\u0000\\u0016\\u0000\\n\\u0000\\u0003\\u0000\\b\\u0000\\u0006\\u0000\\u0014\\u0000\\u0011\\u0000\\u0019\\u0000\\u0017\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002260e99ba54ecad884c209f4a24c0394c32e96b2fe\u0022, \u0022protocol_details\u0022: {\u0022tls_ja3\u0022: \u0022795bc7ce13f60d61e9ac03611dd36d90\u0022, \u0022port\u0022: 3389, \u0022service\u0022: \u0022rdp\u0022, \u0022service_label_fr\u0022: \u0022RDP\u0022}, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffde\ufffdT\ufffdc\ufffdK\ufffd\ufffd\ufffd\ufffd\u0643\ufffd\\r\ufffd\ufffd,\ufffd\ufffd\ufffd\ufffd^]o\ufffd\ufffdEB\ufffd\u003Eh\ufffd\ufffd\ufffd\/\ufffd+\ufffd0\ufffd,\ufffd\ufffd\ufffd\u0027\ufffd#\ufffd\ufffd\\t\ufffd(\ufffd$\ufffd\ufffd\\n\ufffd\ufffd\ufffdgk39\ufffd\ufffd\u003C=\/5\ufffd\u0022, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via RDP:3389 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00223389 \u00b7 RDP\u0022, \u0022emulator_service\u0022: \u0022rdp\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab postgres_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 36.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 40}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 40, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022rdp\u0022, \u0022service_label_fr\u0022: \u0022RDP\u0022, \u0022dst_port\u0022: 3389, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0369\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0369\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022Windows RDP\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022tls_ja3\u0022: \u0022795bc7ce13f60d61e9ac03611dd36d90\u0022, \u0022port\u0022: 3389, \u0022service\u0022: \u0022rdp\u0022, \u0022service_label_fr\u0022: \u0022RDP\u0022}, \u0022attack_vector\u0022: \u0022postgres probe \u00b7 via RDP:3389 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\ufffd\ufffde\ufffdT\ufffdc\ufffdK\ufffd\ufffd\ufffd\ufffd\u0643\ufffd\\r\ufffd\ufffd,\ufffd\ufffd\ufffd\ufffd^]o\ufffd\ufffdEB\ufffd\u003Eh\ufffd\ufffd\ufffd\/\ufffd+\ufffd0\ufffd,\ufffd\ufffd\ufffd\u0027\ufffd#\ufffd\ufffd\\t\ufffd(\ufffd$\ufffd\ufffd\\n\ufffd\ufffd\ufffdgk39\ufffd\ufffd\u003C=\/5\ufffd\u0022, \u0022target_port_label\u0022: \u00223389 \u00b7 RDP\u0022, \u0022emulator_service\u0022: \u0022rdp\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022rdp\u0022, \u0022service_banner\u0022: \u0022Windows RDP\u0022, \u0022service_os\u0022: \u0022windows\u0022, \u0022dst_port\u0022: \u00223389\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022net_rdp_probe\u0022, \u0022rdp_emulated\u0022, \u0022tls_clienthello\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022net_rdp_probe\u0022, \u0022rdp_emulated\u0022, \u0022tls_clienthello\u0022]","anomalies":"[]","severity":6,"bytes_in":207},{"id":8511783,"ip":"198.235.24.240","ts":"2026-06-07 16:55:55.000000","proto":"tcp","src_port":58224,"dst_port":3389,"service":"rdp","classification":"rdp_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022030000130ed000001234000200080000000000\u0022, \u0022emulator_response_len\u0022: 19, \u0022bytes_in\u0022: 451, \u0022payload_entropy\u0022: 3.8391800416313604, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022rdp\u0022, \u0022app_proto\u0022: \u0022rdp\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 3389, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 52.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 52.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 50, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002240bf2c34d73676fee23426938806aaa527b96fcb\u0022, \u0022event_fingerprint\u0022: \u0022ad5bc6c1132c10ce0e88d551a1bd2cf31dc3757e\u0022, \u0022classification_reason\u0022: \u0022N\u00e9gociation protocole RDP \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 116, \u0022precision_signals\u0022: [\u0022pat-0347\u0022, \u0022pat-0348\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0347\u0022, \u0022pat-0348\u0022], \u0022matched_patterns\u0022: [\u0022pat-0347\u0022, \u0022pat-0348\u0022, \u0022pat-0868\u0022, \u0022pat-0768\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022RDP NTLM hash\u0022, \u0022RDP TPKT header\u0022, \u0022ET H.323 setup\u0022, \u0022Mumble ping\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0347\u0022, \u0022pat-0348\u0022, \u0022pat-0868\u0022, \u0022pat-0768\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 52.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 50}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022rdp\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002252ce44b2c3de058cf820cb0f58ebedea\u0022, \u0022path_pattern_hash\u0022: \u00225dd788b551ee7afb63321e74cfc538f6\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 3389, \u0022service\u0022: \u0022rdp\u0022, \u0022service_name\u0022: \u0022rdp\u0022, \u0022risk_score\u0022: 50}, \u0022payload_preview\u0022: \u0022\\u0003\\u0000\\u0000\u0027\\\u0022\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000Cookie: mstshash=ZGQVAsJHK\\r\\n\\u0003\\u0000\\u0001\ufffd\\u0002\ufffd\ufffde\ufffd\\u0001\ufffd\\u0004\\u0001\\u0001\\u0004\\u0001\\u0001\\u0001\\u0001\ufffd0\\u0019\\u0002\\u0001\\\u0022\\u0002\\u0001\\u0002\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0002\ufffd\ufffd\\u0002\\u0001\\u00020\\u0019\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0002\\u0004 \\u0002\\u0001\\u00020\\u001c\\u0002\\u0002\ufffd\ufffd\\u0002\\u0002\ufffd\\u0017\\u0002\\u0002\ufffd\ufffd\u0022, \u0022request_sample\u0022: \u0022\\u0003\\u0000\\u0000\u0027\\\u0022\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000Cookie: mstshash=ZGQVAsJHK\\r\\n\\u0003\\u0000\\u0001\ufffd\\u0002\ufffd\ufffde\ufffd\\u0001\ufffd\\u0004\\u0001\\u0001\\u0004\\u0001\\u0001\\u0001\\u0001\ufffd0\\u0019\\u0002\\u0001\\\u0022\\u0002\\u0001\\u0002\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0002\ufffd\ufffd\\u0002\\u0001\\u00020\\u0019\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0002\\u0004 \\u0002\\u0001\\u00020\\u001c\\u0002\\u0002\ufffd\ufffd\\u0002\\u0002\ufffd\\u0017\\u0002\\u0002\ufffd\ufffd\\u0002\\u0001\\u0001\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0002\ufffd\ufffd\\u0002\\u0001\\u0002\\u0004\ufffd\\u0001\/\\u0000\\u0005\\u0000\\u0014|\\u0000\\u0001\ufffd\u0026\\u0000\\b\\u0000\\u0010\\u0000\\u0001\ufffd\\u0000Duca\ufffd\\u0018\\u0001\ufffd\ufffd\\u0000\\u0004\\u0000\\b\\u0000\\u0000\\u0005 \\u0003\\u0001\ufffd\\u0003\ufffd\\t\\b\\u0000\\u0000(\\n\\u0000\\u0000E\\u0000M\\u0000P\\u0000-\\u0000L\\u0000A\\u0000P\\u0000-\\u00000\\u00000\\u00001\\u00004\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\f\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0003\\u0000\\u0000\u0027\\\u0022\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000Cookie: mstshash=ZGQVAsJHK\\r\\n\\u0003\\u0000\\u0001\ufffd\\u0002\ufffd\ufffde\ufffd\\u0001\ufffd\\u0004\\u0001\\u0001\\u0004\\u0001\\u0001\\u0001\\u0001\ufffd0\\u0019\\u0002\\u0001\\\u0022\\u0002\\u0001\\u0002\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0002\ufffd\ufffd\\u0002\\u0001\\u00020\\u0019\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0002\\u0004 \\u0002\\u0001\\u00020\\u001c\\u0002\\u0002\ufffd\ufffd\\u0002\\u0002\ufffd\\u0017\\u0002\\u0002\ufffd\ufffd\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022\\u0003\\u0000\\u0000\u0027\\\u0022\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000Cookie: mstshash=ZGQVAsJHK\\r\\n\\u0003\\u0000\\u0001\ufffd\\u0002\ufffd\ufffde\ufffd\\u0001\ufffd\\u0004\\u0001\\u0001\\u0004\\u0001\\u0001\\u0001\\u0001\ufffd0\\u0019\\u0002\\u0001\\\u0022\\u0002\\u0001\\u0002\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0002\ufffd\ufffd\\u0002\\u0001\\u00020\\u0019\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0002\\u0004 \\u0002\\u0001\\u00020\\u001c\\u0002\\u0002\ufffd\ufffd\\u0002\\u0002\ufffd\\u0017\\u0002\\u0002\ufffd\ufffd\\u0002\\u0001\\u0001\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0002\ufffd\ufffd\\u0002\\u0001\\u0002\\u0004\ufffd\\u0001\/\\u0000\\u0005\\u0000\\u0014|\\u0000\\u0001\ufffd\u0026\\u0000\\b\\u0000\\u0010\\u0000\\u0001\ufffd\\u0000Duca\ufffd\\u0018\\u0001\ufffd\ufffd\\u0000\\u0004\\u0000\\b\\u0000\\u0000\\u0005 \\u0003\\u0001\ufffd\\u0003\ufffd\\t\\b\\u0000\\u0000(\\n\\u0000\\u0000E\\u0000M\\u0000P\\u0000-\\u0000L\\u0000A\\u0000P\\u0000-\\u00000\\u00000\\u00001\\u00004\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0004\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\f\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000\u0022, \u0022payload_snippet\u0022: \u0022\\u0003\\u0000\\u0000\u0027\\\u0022\ufffd\\u0000\\u0000\\u0000\\u0000\\u0000Cookie: mstshash=ZGQVAsJHK\\r\\n\\u0003\\u0000\\u0001\ufffd\\u0002\ufffd\ufffde\ufffd\\u0001\ufffd\\u0004\\u0001\\u0001\\u0004\\u0001\\u0001\\u0001\\u0001\ufffd0\\u0019\\u0002\\u0001\\\u0022\\u0002\\u0001\\u0002\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0002\ufffd\ufffd\\u0002\\u0001\\u00020\\u0019\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0001\\u0002\\u0001\\u0000\\u0002\\u0001\\u0001\\u0002\\u0002\\u0004 \\u0002\\u0001\\u00020\\u001c\\u0002\\u0002\ufffd\ufffd\\u0002\\u0002\ufffd\\u0017\\u0002\\u0002\ufffd\ufffd\u0022, \u0022classification_reason\u0022: \u0022N\u00e9gociation protocole RDP \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022investigate\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002209e41d2eacac6ba4b85aa85f4dd7375c43045c4f\u0022, \u0022protocol_details\u0022: {\u0022port\u0022: 3389, \u0022service\u0022: \u0022rdp\u0022, \u0022service_label_fr\u0022: \u0022RDP\u0022}, \u0022evidence_snippet\u0022: \u0022\u0027\\\u0022\ufffdCookie: mstshash=ZGQVAsJHK\\r\\n\ufffd\ufffd\ufffde\ufffd\ufffd\ufffd0\\\u0022\ufffd\ufffd0 0\ufffd\ufffd\ufffd\ufffd\ufffd\u0022, \u0022attack_vector\u0022: \u0022rdp probe \u00b7 via RDP:3389 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00223389 \u00b7 RDP\u0022, \u0022emulator_service\u0022: \u0022rdp\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022N\u00e9gociation protocole RDP \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022N\u00e9gociation protocole RDP \u00b7 confiance 100%\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 52.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 50}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 50, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022rdp\u0022, \u0022service_label_fr\u0022: \u0022RDP\u0022, \u0022dst_port\u0022: 3389, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0347\u0022, \u0022pat-0348\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0347\u0022, \u0022pat-0348\u0022], \u0022recommended_action\u0022: \u0022investigate\u0022, \u0022recommended_action_label\u0022: \u0022Investiguer\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022Windows RDP\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022port\u0022: 3389, \u0022service\u0022: \u0022rdp\u0022, \u0022service_label_fr\u0022: \u0022RDP\u0022}, \u0022attack_vector\u0022: \u0022rdp probe \u00b7 via RDP:3389 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022\u0027\\\u0022\ufffdCookie: mstshash=ZGQVAsJHK\\r\\n\ufffd\ufffd\ufffde\ufffd\ufffd\ufffd0\\\u0022\ufffd\ufffd0 0\ufffd\ufffd\ufffd\ufffd\ufffd\u0022, \u0022target_port_label\u0022: \u00223389 \u00b7 RDP\u0022, \u0022emulator_service\u0022: \u0022rdp\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022rdp\u0022, \u0022service_banner\u0022: \u0022Windows RDP\u0022, \u0022service_os\u0022: \u0022windows\u0022, \u0022dst_port\u0022: \u00223389\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_investigate\u0022, \u0022tags_list\u0022: [\u0022net_rdp_cookie\u0022, \u0022rdp_cookie\u0022, \u0022rdp_emulated\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022net_rdp_cookie\u0022, \u0022rdp_cookie\u0022, \u0022rdp_emulated\u0022]","anomalies":"[]","severity":6,"bytes_in":451},{"id":8418172,"ip":"198.235.24.240","ts":"2026-06-06 23:46:16.000000","proto":"tcp","src_port":51436,"dst_port":5910,"service":null,"classification":"port_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 0, \u0022payload_entropy\u0022: 0.0, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 5910, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 48.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 0.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.2, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 48.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 0.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 44, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c47ef9692cdd7a809b4a5289a9a720c5164f54e2\u0022, \u0022event_fingerprint\u0022: \u00220c2f815141fd76b5f5c905904ab86996c5f9d483\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022INT-single-port\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab port_probe \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 48.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 0.0, \u0022novelty\u0022: 0.0, \u0022risk_score\u0022: 44}, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022path_pattern_hash\u0022: \u002249ebffbc8eed300cf9429db1ba4cf66d\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 5910, \u0022risk_score\u0022: 44}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022dd27597eefbd29a936c5c4e7999a724d208284eb\u0022, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022generic\u0022, \u0022service_banner\u0022: \u0022honeypot\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00225910\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022probe\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":0,"bytes_in":0},{"id":8176674,"ip":"198.235.24.240","ts":"2026-06-04 02:07:07.000000","proto":"tcp","src_port":61772,"dst_port":2087,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u002219e29534fd49dd27d09234e639c4057e\u0022, \u0022tls_sni\u0022: null, \u0022tls_weak_cipher\u0022: true, \u0022tls_weak_cipher_count\u0022: 4, \u0022bytes_in\u0022: 243, \u0022payload_entropy\u0022: 5.826775903938798, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 2087, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 30.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 6, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 30.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 26, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00229dd8f5c85a887493f1e796c0616b327e9c11f965\u0022, \u0022event_fingerprint\u0022: \u0022c12122c2e625214e3c08c4f3b2f91b9d3850d755\u0022, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022ja3\u0022: \u002219e29534fd49dd27d09234e639c4057e\u0022, \u0022payload_hash\u0022: \u0022fd82eece1ccebe9f7962dbdb083d325c\u0022, \u0022path_pattern_hash\u0022: \u00228792d2cfdc5028123bfb8f159de8656c\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 2087, \u0022service\u0022: \u0022tls\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022confidence\u0022: 0.74, \u0022classification_confidence\u0022: 0.74, \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003B\\u001c\ufffd\ufffd \\u000bim9\\u0001\ufffd\ufffd\ufffd \ufffd$\\u0000\ufffd\ufffd\ufffd\ufffd\\u0017\ufffdn\ufffd%\u07db\ufffd,\ufffd\ufffd \ufffd4%\\u0003#\ufffd~-\\u000bGo\ufffdw\u43d07\u003Ch\ufffd\/\ufffd\ufffd\ufffd\\u0013\ufffd\ufffd?z\ufffd\\u0000\u0026\ufffd+\ufffd\/\ufffd,\ufffd0\u0329\u0328\ufffd\\t\ufffd\\u0013\ufffd\\n\ufffd\\u0014\\u0000\ufffd\\u0000\ufffd\\u0000\/\\u00005\ufffd\\u0012\\u0000\\n\\u0013\\u0001\\u0013\\u0002\\u0013\\u0003\\u0001\\u0000\\u0000{\\u0000\\u0005\\u0000\\u0005\\u0001\\u0000\\u0000\\u0000\u0022, \u0022event_signature\u0022: \u00224253d07e1eeb547486f13391f9318a1d32e64dfe\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":"19e29534fd49dd27d09234e639c4057e","tls_ja3":"771,49195-49199-49196-49200-52393-52392-49161-49171-49162-49172-156-157-47-53-49170-10-4865-4866-4867,5-10-11-13-65281-18-43-51,29-23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022]","anomalies":"[]","severity":4,"bytes_in":243},{"id":8176675,"ip":"198.235.24.240","ts":"2026-06-04 02:07:07.000000","proto":"tcp","src_port":59446,"dst_port":2087,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022795bc7ce13f60d61e9ac03611dd36d90\u0022, \u0022tls_sni\u0022: null, \u0022tls_weak_cipher\u0022: true, \u0022tls_weak_cipher_count\u0022: 29, \u0022bytes_in\u0022: 207, \u0022payload_entropy\u0022: 4.9260344959498505, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 2087, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 30.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 6, \u0022risk_granularity\u0022: 2.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 30.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 26, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00229dd8f5c85a887493f1e796c0616b327e9c11f965\u0022, \u0022event_fingerprint\u0022: \u00226267d4d6344dbf705c3d690c1775833bbeae0f43\u0022, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022ja3\u0022: \u0022795bc7ce13f60d61e9ac03611dd36d90\u0022, \u0022payload_hash\u0022: \u002218fbefef89a60219c9ced329368a9099\u0022, \u0022path_pattern_hash\u0022: \u00228792d2cfdc5028123bfb8f159de8656c\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 2087, \u0022service\u0022: \u0022tls\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022confidence\u0022: 0.74, \u0022classification_confidence\u0022: 0.74, \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022payload_preview\u0022: \u0022\\u0016\\u0003\\u0001\\u0000\ufffd\\u0001\\u0000\\u0000\ufffd\\u0003\\u0003\ufffdg\ufffd9\ufffd;\ufffdf\ufffd\\\\\ufffd\ufffd;\\u0007\ufffd8\ufffd\ufffd\ufffd\ufffd\ufffd\\rW\ufffd\ufffd]!\ufffdM\u0027\\u0000\\u0000h\ufffd\\u0014\ufffd\\u0013\ufffd\/\ufffd+\ufffd0\ufffd,\ufffd\\u0011\ufffd\\u0007\ufffd\u0027\ufffd#\ufffd\\u0013\ufffd\\t\ufffd(\ufffd$\ufffd\\u0014\ufffd\\n\ufffd\\u0015\\u0000\ufffd\\u0000\ufffd\\u0000g\\u0000k\\u00003\\u00009\\u0000\ufffd\\u0000\ufffd\\u0000\\u0005\\u0000\\u0004\\u0000\u003C\\u0000=\\u0000\/\\u00005\ufffd\\u0012\\u0000\\u0016\\u0000\\n\\u0000\\u0003\\u0000\\b\\u0000\\u0006\\u0000\\u0014\\u0000\\u0011\\u0000\\u0019\\u0000\\u0017\u0022, \u0022event_signature\u0022: \u002212ee47157578e5699def648f3f015177625d4c85\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":"795bc7ce13f60d61e9ac03611dd36d90","tls_ja3":"771,52244-52243-49199-49195-49200-49196-49169-49159-49191-49187-49171-49161-49192-49188-49172-49162-52245-158-159-103-107-51-57-156-157-5-4-60-61-47-53-49170-22-10-3-8-6-20-17-25-23-50-49160-18-19-21-56-64-102-106-162-163,5-10-11-13-65281-15,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022, \u0022tls_weak_cipher\u0022]","anomalies":"[]","severity":4,"bytes_in":207},{"id":8169064,"ip":"198.235.24.240","ts":"2026-06-03 22:21:08.000000","proto":"tcp","src_port":56681,"dst_port":16010,"service":"http","classification":"web_scanner","waf_score":23,"waf_tags":"[\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 2, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022689bfbab10519e1ecf247982c128c7460ee59d4d\u0022, \u0022http_host_hash\u0022: null, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 185, \u0022payload_entropy\u0022: 4.938089755714326, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 16010, \u0022risk_waf\u0022: 57.5, \u0022risk_classification\u0022: 48.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 57.5, \u0022classification\u0022: 48.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 42, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00225f60db14b24ca9291066c0eb883d30fcd1643d9d\u0022, \u0022event_fingerprint\u0022: \u0022b2e07cdb958b18fd76da4c2826993ae15435453f\u0022, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022ce3935d92be5f9290d282e51ab604b41\u0022, \u0022payload_hash\u0022: \u0022408dddfd3211eda1263e9161f0d91c4d\u0022, \u0022path_pattern_hash\u0022: \u00228a5edab282632443219e051e4ade2d1d\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 16010, \u0022service\u0022: \u0022http\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022threat_family\u0022: [\u0022disclosed_scanner\u0022], \u0022confidence\u0022: 0.95, \u0022classification_confidence\u0022: 0.95, \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.0\\r\\nUser-Agent: Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks\u0022, \u0022event_signature\u0022: \u002248c20f765b14261b3d82b706c938548f2a0040fc\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_ua_disclosed_scanner\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.0","http_host":null,"http_user_agent":"Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks.com\/r\/1\/Cortex-Xpanse\/Scanning-activity","http_referer":null,"tags":"[\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_ua_disclosed_scanner\u0022]","anomalies":"[]","severity":3,"bytes_in":185},{"id":8072091,"ip":"198.235.24.240","ts":"2026-06-01 02:29:05.000000","proto":"tcp","src_port":51570,"dst_port":987,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u002218e9afaf91db6f8a2470e7435c2a1d6b\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 372, \u0022payload_entropy\u0022: 6.827478645460878, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022c89c178b0e8c9e433108fc340cb251d4823d6657\u0022, \u0022event_fingerprint\u0022: \u0022143445bfc4053e031e6b52c8b4dc4f7b30ccd04a\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"18e9afaf91db6f8a2470e7435c2a1d6b","tls_ja3":"770,49162-49172-57-107-53-61-49159-49161-49187-49169-49171-49191-51-103-50-5-4-47-60-10,61184-65281-10-11-35-13172-30031-5,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":372},{"id":8050894,"ip":"198.235.24.240","ts":"2026-05-31 15:53:11.000000","proto":"tcp","src_port":59322,"dst_port":8022,"service":null,"classification":"port_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 0, \u0022payload_entropy\u0022: 0.0, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 0, \u0022campaign_key\u0022: \u00228778434242a5e64d4a6ddb8eb966e0c2bd62430e\u0022, \u0022event_fingerprint\u0022: \u002255eb5fe396bc3cc73ce7467ba794ffe7bbf64cff\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":0,"bytes_in":0},{"id":7957191,"ip":"198.235.24.240","ts":"2026-05-29 21:30:21.000000","proto":"tcp","src_port":63538,"dst_port":20257,"service":null,"classification":"port_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 14, \u0022payload_entropy\u0022: 3.521640636343319, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 0, \u0022campaign_key\u0022: \u0022fa159067ea7ef6a6ed6a1ede48eeb1c0074f844b\u0022, \u0022event_fingerprint\u0022: \u0022fed85086d8bc339325a7aa43c8f33e9498a11b71\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":0,"bytes_in":14},{"id":7954226,"ip":"198.235.24.240","ts":"2026-05-29 20:27:50.000000","proto":"tcp","src_port":64836,"dst_port":8883,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022795bc7ce13f60d61e9ac03611dd36d90\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 207, \u0022payload_entropy\u0022: 4.907912032546405, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022e325f114a52c45b0890104d913fe885b12e3a798\u0022, \u0022event_fingerprint\u0022: \u0022798245cdd3c55d195c36cfa332cab9c4339c9322\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"795bc7ce13f60d61e9ac03611dd36d90","tls_ja3":"771,52244-52243-49199-49195-49200-49196-49169-49159-49191-49187-49171-49161-49192-49188-49172-49162-52245-158-159-103-107-51-57-156-157-5-4-60-61-47-53-49170-22-10-3-8-6-20-17-25-23-50-49160-18-19-21-56-64-102-106-162-163,5-10-11-13-65281-15,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":207},{"id":7954225,"ip":"198.235.24.240","ts":"2026-05-29 20:27:49.000000","proto":"tcp","src_port":64822,"dst_port":8883,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u00222196848d251b217de8b2c037e356c11d\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 1483, \u0022payload_entropy\u0022: 7.730665180852338, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022e325f114a52c45b0890104d913fe885b12e3a798\u0022, \u0022event_fingerprint\u0022: \u002299f676f7832444623b86f5cef25b4d657d00d221\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"2196848d251b217de8b2c037e356c11d","tls_ja3":"771,49195-49199-49196-49200-52393-52392-49161-49171-49162-49172-4865-4866-4867,11-65281-23-18-5-10-13-50-43-51,4588-29-23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":1483},{"id":7911998,"ip":"198.235.24.240","ts":"2026-05-28 23:57:27.000000","proto":"tcp","src_port":59204,"dst_port":8020,"service":"http","classification":"web_attack","waf_score":23,"waf_tags":"[\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 3, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022689bfbab10519e1ecf247982c128c7460ee59d4d\u0022, \u0022http_host_hash\u0022: \u0022484629fbfedce591fd570c43c91ddc8f3cbc73ab\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 218, \u0022payload_entropy\u0022: 5.100647144002227, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u00225dc1a5fa114130cd97ada022e9306ea420b250bf\u0022, \u0022event_fingerprint\u0022: \u0022e7aa3deaadb03b61331a5255954d3b45fd1b4007\u0022, \u0022tags_list\u0022: [\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8020","http_user_agent":"Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks.com\/r\/1\/Cortex-Xpanse\/Scanning-activity","http_referer":null,"tags":"[\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":10,"bytes_in":218},{"id":7821439,"ip":"198.235.24.240","ts":"2026-05-27 22:58:22.000000","proto":"tcp","src_port":53086,"dst_port":2484,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u002218e9afaf91db6f8a2470e7435c2a1d6b\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 372, \u0022payload_entropy\u0022: 6.827478645460878, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022f8e7ae407383ca1ce6fecb17a18509bf48359d66\u0022, \u0022event_fingerprint\u0022: \u0022568ddf47512c4836708d96028f96ee8136352fe2\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"18e9afaf91db6f8a2470e7435c2a1d6b","tls_ja3":"770,49162-49172-57-107-53-61-49159-49161-49187-49169-49171-49191-51-103-50-5-4-47-60-10,61184-65281-10-11-35-13172-30031-5,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":372},{"id":7816354,"ip":"198.235.24.240","ts":"2026-05-27 20:03:24.000000","proto":"tcp","src_port":64968,"dst_port":1883,"service":"mqtt","classification":"mqtt_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 18, \u0022payload_entropy\u0022: 3.1279868068776753, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mqtt\u0022, \u0022app_proto\u0022: \u0022mqtt\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 50, \u0022campaign_key\u0022: \u00220d65484148f9793655bb581277303ea528f89944\u0022, \u0022event_fingerprint\u0022: \u0022cfbc4bf6c6ba306df7f60198b2c1e3ee0dcb8f30\u0022, \u0022tags_list\u0022: [\u0022mqtt_connect\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mqtt_connect\u0022]","anomalies":"[]","severity":4,"bytes_in":18},{"id":7768808,"ip":"198.235.24.240","ts":"2026-05-27 00:16:55.000000","proto":"tcp","src_port":63516,"dst_port":1717,"service":"http","classification":"web_attack","waf_score":23,"waf_tags":"[\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 3, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022689bfbab10519e1ecf247982c128c7460ee59d4d\u0022, \u0022http_host_hash\u0022: \u00220e7cddfca05bc734e8f69a8802b6b4f5cb2ce93a\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 218, \u0022payload_entropy\u0022: 5.091014733588879, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022e1585c1eb58449817b4fc4b37b699cf0fa8fcc7a\u0022, \u0022event_fingerprint\u0022: \u002248671016b7a2b26d8bce7dbf69be9659a11f7b6c\u0022, \u0022tags_list\u0022: [\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:1717","http_user_agent":"Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks.com\/r\/1\/Cortex-Xpanse\/Scanning-activity","http_referer":null,"tags":"[\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":10,"bytes_in":218},{"id":7639148,"ip":"198.235.24.240","ts":"2026-05-24 03:40:21.000000","proto":"tcp","src_port":63404,"dst_port":20256,"service":null,"classification":"port_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 14, \u0022payload_entropy\u0022: 3.378783493486176, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 0, \u0022campaign_key\u0022: \u0022ee5415bf160646f2a7333b36e4123bd316165308\u0022, \u0022event_fingerprint\u0022: \u0022c2c43719be593f3ab3360773f7c6c167181e64cd\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":0,"bytes_in":14},{"id":7568648,"ip":"198.235.24.240","ts":"2026-05-23 02:15:02.000000","proto":"tcp","src_port":62406,"dst_port":8020,"service":"http","classification":"web_attack","waf_score":23,"waf_tags":"[\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 3, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022689bfbab10519e1ecf247982c128c7460ee59d4d\u0022, \u0022http_host_hash\u0022: \u0022484629fbfedce591fd570c43c91ddc8f3cbc73ab\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 218, \u0022payload_entropy\u0022: 5.100647144002227, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u00225dc1a5fa114130cd97ada022e9306ea420b250bf\u0022, \u0022event_fingerprint\u0022: \u0022e7aa3deaadb03b61331a5255954d3b45fd1b4007\u0022, \u0022tags_list\u0022: [\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8020","http_user_agent":"Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks.com\/r\/1\/Cortex-Xpanse\/Scanning-activity","http_referer":null,"tags":"[\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":10,"bytes_in":218},{"id":7413071,"ip":"198.235.24.240","ts":"2026-05-20 18:58:15.000000","proto":"tcp","src_port":63332,"dst_port":25789,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u002219e29534fd49dd27d09234e639c4057e\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 243, \u0022payload_entropy\u0022: 5.889786148414919, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022dfa5a1fca71e3fd4c7da73264f252603165731a2\u0022, \u0022event_fingerprint\u0022: \u0022b6584fdf388a5a67fedffae8bc66c502de86dfd8\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"19e29534fd49dd27d09234e639c4057e","tls_ja3":"771,49195-49199-49196-49200-52393-52392-49161-49171-49162-49172-156-157-47-53-49170-10-4865-4866-4867,5-10-11-13-65281-18-43-51,29-23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":243},{"id":7413072,"ip":"198.235.24.240","ts":"2026-05-20 18:58:15.000000","proto":"tcp","src_port":63338,"dst_port":25789,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022795bc7ce13f60d61e9ac03611dd36d90\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 207, \u0022payload_entropy\u0022: 4.955020003196226, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022dfa5a1fca71e3fd4c7da73264f252603165731a2\u0022, \u0022event_fingerprint\u0022: \u0022175c20f1e0d83429d9f09817e8f5916b24245dd0\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"795bc7ce13f60d61e9ac03611dd36d90","tls_ja3":"771,52244-52243-49199-49195-49200-49196-49169-49159-49191-49187-49171-49161-49192-49188-49172-49162-52245-158-159-103-107-51-57-156-157-5-4-60-61-47-53-49170-22-10-3-8-6-20-17-25-23-50-49160-18-19-21-56-64-102-106-162-163,5-10-11-13-65281-15,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":207},{"id":7366504,"ip":"198.235.24.240","ts":"2026-05-20 00:26:13.000000","proto":"tcp","src_port":55683,"dst_port":5289,"service":null,"classification":"port_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 0, \u0022payload_entropy\u0022: 0.0, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 0, \u0022campaign_key\u0022: \u0022ebe2aa6371f1c5311037327d5af5394ad3adcb59\u0022, \u0022event_fingerprint\u0022: \u0022d52e0561f14f782130464484caa78ad8e0f7cc07\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":0,"bytes_in":0},{"id":7362760,"ip":"198.235.24.240","ts":"2026-05-19 23:51:38.000000","proto":"tcp","src_port":57323,"dst_port":7547,"service":"http","classification":"web_attack","waf_score":23,"waf_tags":"[\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 2, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022689bfbab10519e1ecf247982c128c7460ee59d4d\u0022, \u0022http_host_hash\u0022: null, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 185, \u0022payload_entropy\u0022: 4.938089755714326, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u002208f3da32e8470d895f5e91f41ca002b677fbcac3\u0022, \u0022event_fingerprint\u0022: \u0022c8752c37034632ca0deafd712cf3d045fd8726cc\u0022, \u0022tags_list\u0022: [\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.0","http_host":null,"http_user_agent":"Hello from Palo Alto Networks, find out more about our scans in https:\/\/docs-cortex.paloaltonetworks.com\/r\/1\/Cortex-Xpanse\/Scanning-activity","http_referer":null,"tags":"[\u0022950318:lfi-14\u0022, \u0022950406:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":10,"bytes_in":185},{"id":7342629,"ip":"198.235.24.240","ts":"2026-05-19 19:44:13.000000","proto":"tcp","src_port":49278,"dst_port":5907,"service":null,"classification":"port_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 0, \u0022payload_entropy\u0022: 0.0, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 0, \u0022campaign_key\u0022: \u0022ee3ee7dda786d7a19813eb058a585418be17ccd7\u0022, \u0022event_fingerprint\u0022: \u0022efd7fe1b9421aa97eaa5060e8d19ccd5eb5070be\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":0,"bytes_in":0},{"id":7290153,"ip":"198.235.24.240","ts":"2026-05-19 05:30:41.000000","proto":"tcp","src_port":63442,"dst_port":8088,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u002219e29534fd49dd27d09234e639c4057e\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 243, \u0022payload_entropy\u0022: 5.769685954813956, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u00227f9e076ea4caf80e331e644161ba4c4470d379b8\u0022, \u0022event_fingerprint\u0022: \u002264b0ef96b8d051fa81a22052c791a78856017fd5\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"19e29534fd49dd27d09234e639c4057e","tls_ja3":"771,49195-49199-49196-49200-52393-52392-49161-49171-49162-49172-156-157-47-53-49170-10-4865-4866-4867,5-10-11-13-65281-18-43-51,29-23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":243},{"id":7290154,"ip":"198.235.24.240","ts":"2026-05-19 05:30:41.000000","proto":"tcp","src_port":63458,"dst_port":8088,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022795bc7ce13f60d61e9ac03611dd36d90\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 207, \u0022payload_entropy\u0022: 4.932049532171281, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u00227f9e076ea4caf80e331e644161ba4c4470d379b8\u0022, \u0022event_fingerprint\u0022: \u00223f89c934190c014bf0179de0748ec62f0deb4a39\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"795bc7ce13f60d61e9ac03611dd36d90","tls_ja3":"771,52244-52243-49199-49195-49200-49196-49169-49159-49191-49187-49171-49161-49192-49188-49172-49162-52245-158-159-103-107-51-57-156-157-5-4-60-61-47-53-49170-22-10-3-8-6-20-17-25-23-50-49160-18-19-21-56-64-102-106-162-163,5-10-11-13-65281-15,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":207},{"id":7288596,"ip":"198.235.24.240","ts":"2026-05-19 04:58:10.000000","proto":"tcp","src_port":59948,"dst_port":2001,"service":null,"classification":"port_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 0, \u0022payload_entropy\u0022: 0.0, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 0, \u0022campaign_key\u0022: \u00221e5e319ed345364f04ea073684960b562df31677\u0022, \u0022event_fingerprint\u0022: \u00225ebf9983e0d60a6267bb52fd2c108c8b62d9fe4c\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":0,"bytes_in":0}],"total_events":31}