{"ip":"34.47.80.115","exported_at":"2026-06-18T20:06:16+00:00","period_days":30,"metrics":{"events7d":332,"distinct_ports":1,"distinct_classifications":6,"max_severity":7,"last_sensor_id":"paris-1","max_waf_score":null,"max_risk_score":52,"attack_stage":"exploit_attempt","attack_chain_stage":"exploitation","threat_family":["ddos"],"recommended_action":"monitor","confidence":0,"risk_breakdown":{"waf":8,"classification":79,"behavior":0,"geo":40,"protocol":40,"novelty":15},"mitre_tactics":["TA0001","TA0002"],"mitre_technique":"TA0001","top_mitre_technique":"TA0007","top_mitre_count":235,"executive_one_liner_fr":"Activit\u00e9 suspecte \u2014 risque 34\/100 (Faible) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE","campaign_hint_fr":null,"confidence_breakdown":{"waf":8,"classification":79,"behavior":0,"geo":40,"protocol":40,"novelty":15,"risk_score":34},"persona_hostname":"mail.sensor-1.internal","correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":0,"confidence_hint_fr":"Confiance mod\u00e9r\u00e9e \u2014 signal unique","sensor_role_label_fr":"Renseignement menaces","tags_summary_labels_fr":[],"tags_summary":[],"attack_vector":"syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)","protocol_details":{"payload_preview":"GET \/backend\/sendgrid.env HTTP\/1.1\r\nHost: 62.3.50.33:8020\r\nUser-Agent: NetSurf\/1.2 (NetBSD; amd64)\r\nAccept-Charset: utf-8\r\nAccep","port":8020,"service":"hdfs-namenode","service_label_fr":"HDFS NAMENODE"},"protocol_summary_fr":"Payload GET \/backend\/sendgrid.env HTTP\/1.1\r\nHost: 62.3.50.33:8020\r\nUser\u2026 \u00b7 HDFS NAMENODE:8020","evidence_snippet":"GET \/backend\/sendgrid.env HTTP\/1.1\r\nHost: 62.3.50.33:8020\r\nUser-Agent: NetSurf\/1.2 (NetBSD; amd64)\r\nAccept-Charset: utf-8\r\nAccep","target_port_label":"8020 \u00b7 HDFS NAMENODE","emulator_service":"hdfs-namenode","confidence_reason":"Confiance 0 % \u2014 4 signal(aux) capteur","classification_reason":"Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%","classification_reason_label_fr":"Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%","confidence_factors_fr":null,"payload_preview":"GET \/backend\/sendgrid.env HTTP\/1.1\r\nHost: 62.3.50.33:8020\r\nUser-Agent: NetSurf\/1.2 (NetBSD; amd64)\r\nAccept-Charset: utf-8\r\nAccep"},"events":[{"id":8978516,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34636,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 262, \u0022payload_entropy\u0022: 5.425921831212348, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022ddcbe73b25a19b58f4ea67ca3f85261d\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/server\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; VOG-L29) AppleWebKit\/537\u0022, \u0022request_sample\u0022: \u0022GET \/server\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; VOG-L29) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.111 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: clo\u0022, \u0022payload_snippet\u0022: \u0022GET \/server\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; VOG-L29) AppleWebKit\/537\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/server\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; VOG-L29) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.111 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: clo\u0022, \u0022payload_snippet\u0022: \u0022GET \/server\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; VOG-L29) AppleWebKit\/537\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022b354700593aa59f1b0bc8e3c5bea7248f3b20689\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/server\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; VOG-L29) AppleWebKit\/537\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/server\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; VOG-L29) AppleWebKit\/537\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/server\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; VOG-L29) AppleWebKit\/537\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/server\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; VOG-L29) AppleWebKit\/537\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":262},{"id":8978517,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34648,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 248, \u0022payload_entropy\u0022: 5.425086148618453, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022e43f41bad329ecceab323de7e2647311\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/var\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit\/537.36 (K\u0022, \u0022request_sample\u0022: \u0022GET \/var\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.87 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/var\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit\/537.36 (K\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/var\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.87 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/var\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit\/537.36 (K\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00224151a648577cbdf8478c9f82714483d282aaf530\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/var\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit\/537.36 (K\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/var\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit\/537.36 (K\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/var\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit\/537.36 (K\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/var\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit\/537.36 (K\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":248},{"id":8978518,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34652,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 303, \u0022payload_entropy\u0022: 5.440489124403433, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002265090852c332540839f31aaec1e65e5f\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/release\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWeb\u0022, \u0022request_sample\u0022: \u0022GET \/release\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit\/605.1.15 (KHTML, like Gecko) Mobile\/15G77 MicroMessenger\/7.0.3(0x17000321) NetType\/WIFI Language\/zh_CN\\r\\nAccept-Charset: utf-\u0022, \u0022payload_snippet\u0022: \u0022GET \/release\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWeb\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/release\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit\/605.1.15 (KHTML, like Gecko) Mobile\/15G77 MicroMessenger\/7.0.3(0x17000321) NetType\/WIFI Language\/zh_CN\\r\\nAccept-Charset: utf-\u0022, \u0022payload_snippet\u0022: \u0022GET \/release\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWeb\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022790c97e176ef3322315b009b9a9c79dae3cf137f\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/release\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWeb\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/release\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWeb\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/release\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWeb\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/release\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWeb\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":303},{"id":8978519,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34726,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 291, \u0022payload_entropy\u0022: 5.429409347293247, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 44, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022fe877a7756155d2222a1b1375c595b0011e73afe\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 44}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022dbf64438907adee3012bbc1aa83a0dca\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 44}, \u0022payload_preview\u0022: \u0022GET \/config\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit\/\u0022, \u0022request_sample\u0022: \u0022GET \/config\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/75.0.3770.100 YaBrowser\/19.7.0.1990 Yowser\/2.5 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-En\u0022, \u0022payload_snippet\u0022: \u0022GET \/config\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit\/\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/config\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/75.0.3770.100 YaBrowser\/19.7.0.1990 Yowser\/2.5 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-En\u0022, \u0022payload_snippet\u0022: \u0022GET \/config\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit\/\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022cf2c3a3a77c32a1d1a94e33484608c50357a7d75\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/config\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit\/\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/config\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit\/\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 6 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 44\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 44}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 44, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/config\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit\/\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/config\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit\/\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 6 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022, \u0022redis_config_probe\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022, \u0022redis_config_probe\u0022]","anomalies":"[]","severity":7,"bytes_in":291},{"id":8978520,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34740,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 212, \u0022payload_entropy\u0022: 5.303107816199932, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00225e398e2ead6480fc0d44ea692af2f1f4\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/private\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; FreeBSD amd64; rv:54.0) Gecko\/201001\u0022, \u0022request_sample\u0022: \u0022GET \/private\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; FreeBSD amd64; rv:54.0) Gecko\/20100101 Firefox\/54.0\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/private\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; FreeBSD amd64; rv:54.0) Gecko\/201001\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/private\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; FreeBSD amd64; rv:54.0) Gecko\/20100101 Firefox\/54.0\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/private\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; FreeBSD amd64; rv:54.0) Gecko\/201001\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002232e9fbd12627925cfe157c2e68196e82e7582dbe\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/private\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; FreeBSD amd64; rv:54.0) Gecko\/201001\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/private\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; FreeBSD amd64; rv:54.0) Gecko\/201001\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/private\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; FreeBSD amd64; rv:54.0) Gecko\/201001\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/private\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; FreeBSD amd64; rv:54.0) Gecko\/201001\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":212},{"id":8978521,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34742,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 251, \u0022payload_entropy\u0022: 5.381634308842309, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.6, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 44, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022fe877a7756155d2222a1b1375c595b0011e73afe\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 44}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022da16046533f8af8ee84a4478e667a890\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 44}, \u0022payload_preview\u0022: \u0022GET \/config\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; Pixel 3a) AppleWebKit\/537.36 (KHTML\u0022, \u0022request_sample\u0022: \u0022GET \/config\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; Pixel 3a) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.89 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/config\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; Pixel 3a) AppleWebKit\/537.36 (KHTML\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/config\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; Pixel 3a) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.89 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/config\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; Pixel 3a) AppleWebKit\/537.36 (KHTML\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00227d00608a11b4b0b81f928653219c4001f88479d1\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/config\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; Pixel 3a) AppleWebKit\/537.36 (KHTML\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/config\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; Pixel 3a) AppleWebKit\/537.36 (KHTML\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 6 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 44\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 44}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 44, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/config\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; Pixel 3a) AppleWebKit\/537.36 (KHTML\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/config\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; Pixel 3a) AppleWebKit\/537.36 (KHTML\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 6 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022, \u0022redis_config_probe\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022, \u0022redis_config_probe\u0022]","anomalies":"[]","severity":7,"bytes_in":251},{"id":8978522,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34658,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 155, \u0022payload_entropy\u0022: 5.1348841792107445, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.9, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 34, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00224c534dfcbc4ff30ad0edf86865b3d75c7daa6ecf\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 34}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002258ecba3d1e1669f81223f7581d5e296e\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 34}, \u0022payload_preview\u0022: \u0022GET \/packages\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Web Downloader\/6.9\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: \u0022, \u0022request_sample\u0022: \u0022GET \/packages\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Web Downloader\/6.9\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/packages\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Web Downloader\/6.9\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding:\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/packages\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Web Downloader\/6.9\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/packages\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Web Downloader\/6.9\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding:\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002212022c5e2bb70a2a0707d388bfc68c7fb4a6378f\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/packages\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Web Downloader\/6.9\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding:\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/packages\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Web Downloader\/6.9\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding:\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 4 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 34\/100 (Faible) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 34}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 34, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/packages\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Web Downloader\/6.9\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding:\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/packages\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Web Downloader\/6.9\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding:\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 4 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":155},{"id":8978523,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34698,"dst_port":8020,"service":"hdfs-namenode","classification":"elasticsearch_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 255, \u0022payload_entropy\u0022: 5.421022272490135, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 49, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab elasticsearch_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022confidence\u0022: 0.49, \u0022classification_confidence\u0022: 0.49, \u0022precision_score\u0022: 58, \u0022precision_signals\u0022: [\u0022pat-0341\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0341\u0022], \u0022matched_patterns\u0022: [\u0022pat-0341\u0022], \u0022matched_pattern_names\u0022: [\u0022ES admin GET\u0022], \u0022pattern_ids\u0022: [\u0022pat-0341\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 49}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 49.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00228ff5d46dd92a90c7e805a0b54ea3e675\u0022, \u0022path_pattern_hash\u0022: \u00229dbf5366f59d9174076d704198d3d3fd\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 49}, \u0022payload_preview\u0022: \u0022GET \/admin\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960W) AppleWebKit\/537.36 (KH\u0022, \u0022request_sample\u0022: \u0022GET \/admin\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960W) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.111 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/admin\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960W) AppleWebKit\/537.36 (KH\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/admin\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960W) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.111 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/admin\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960W) AppleWebKit\/537.36 (KH\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab elasticsearch_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002208bc0bc6f247515df42b98e32fb8b1961401abe1\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/admin\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960W) AppleWebKit\/537.36 (KH\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/admin\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960W) AppleWebKit\/537.36 (KH\u0022, \u0022attack_vector\u0022: \u0022elasticsearch probe \u00b7 via HDFS NAMENODE:8020 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab elasticsearch_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab elasticsearch_probe \u00bb (signaux protocolaires) \u00b7 confiance 49%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 49\/100\u0022, \u0022confidence_pct\u0022: 49, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 49}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 49, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022pat-0341\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022pat-0341\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/admin\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960W) AppleWebKit\/537.36 (KH\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022elasticsearch probe \u00b7 via HDFS NAMENODE:8020 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/admin\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960W) AppleWebKit\/537.36 (KH\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 49 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 49 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":255},{"id":8978524,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34684,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 255, \u0022payload_entropy\u0022: 5.425830088818634, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00229e5f3a3dd1ea4e9023acf65fc624f33b\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/frontend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537\u0022, \u0022request_sample\u0022: \u0022GET \/frontend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/75.0.3770.142 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/frontend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/frontend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/75.0.3770.142 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/frontend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022a8cd517596b1483442aa0ab3d3bc3a66c473c600\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/frontend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/frontend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/frontend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/frontend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":255},{"id":8978525,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34754,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 405, \u0022payload_entropy\u0022: 5.566777406101932, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002248515512c84564c597dbcf736d159638\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/laravel\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 6.0.1; OPPO A57 Build\/MMB29M; wv) App\u0022, \u0022request_sample\u0022: \u0022GET \/laravel\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 6.0.1; OPPO A57 Build\/MMB29M; wv) AppleWebKit\/537.36 (KHTML, like Gecko) Version\/4.0 Chrome\/66.0.3359.126 MQQBrowser\/6.2 TBS\/044813 Mobile Safari\/537.36 MMWEBID\/6886\u0022, \u0022payload_snippet\u0022: \u0022GET \/laravel\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 6.0.1; OPPO A57 Build\/MMB29M; wv) App\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/laravel\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 6.0.1; OPPO A57 Build\/MMB29M; wv) AppleWebKit\/537.36 (KHTML, like Gecko) Version\/4.0 Chrome\/66.0.3359.126 MQQBrowser\/6.2 TBS\/044813 Mobile Safari\/537.36 MMWEBID\/6886\u0022, \u0022payload_snippet\u0022: \u0022GET \/laravel\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 6.0.1; OPPO A57 Build\/MMB29M; wv) App\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002267dcd5ba4a72ef86e7ca686d6d960348dc736204\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/laravel\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 6.0.1; OPPO A57 Build\/MMB29M; wv) App\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/laravel\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 6.0.1; OPPO A57 Build\/MMB29M; wv) App\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/laravel\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 6.0.1; OPPO A57 Build\/MMB29M; wv) App\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/laravel\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 6.0.1; OPPO A57 Build\/MMB29M; wv) App\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":405},{"id":8978526,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34680,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 258, \u0022payload_entropy\u0022: 5.411905080823147, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002296631aff4ea6c0dc0ebd7d574e511623\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/services\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_13_0) AppleWebKit\/\u0022, \u0022request_sample\u0022: \u0022GET \/services\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_13_0) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/74.0.3729.169 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/services\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_13_0) AppleWebKit\/\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/services\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_13_0) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/74.0.3729.169 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/services\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_13_0) AppleWebKit\/\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00221a257874be39c15f1bd552e296f8fb7c4b98cb2e\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/services\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_13_0) AppleWebKit\/\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/services\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_13_0) AppleWebKit\/\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/services\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_13_0) AppleWebKit\/\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/services\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_13_0) AppleWebKit\/\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":258},{"id":8978527,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34710,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 258, \u0022payload_entropy\u0022: 5.384045347987969, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022094748c9581cf86aa215ae0eaf89359b\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/frontend\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKi\u0022, \u0022request_sample\u0022: \u0022GET \/frontend\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/77.0.3835.0 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/frontend\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKi\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/frontend\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/77.0.3835.0 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/frontend\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKi\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002234b87b63e1859524c7b6ad8ee2e98c942c16542b\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/frontend\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKi\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/frontend\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKi\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/frontend\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKi\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/frontend\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKi\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":258},{"id":8978528,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34664,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 254, \u0022payload_entropy\u0022: 5.385016878368065, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002224c7775b62d028fdbcd330f9dea8c805\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/portal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.0.0; LG-H873) AppleWebKit\/537.36 (KH\u0022, \u0022request_sample\u0022: \u0022GET \/portal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.0.0; LG-H873) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.89 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/portal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.0.0; LG-H873) AppleWebKit\/537.36 (KH\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/portal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.0.0; LG-H873) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.89 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/portal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.0.0; LG-H873) AppleWebKit\/537.36 (KH\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022045351ddf94709a023c5f56e5d292b2d17916dcd\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/portal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.0.0; LG-H873) AppleWebKit\/537.36 (KH\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/portal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.0.0; LG-H873) AppleWebKit\/537.36 (KH\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/portal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.0.0; LG-H873) AppleWebKit\/537.36 (KH\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/portal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.0.0; LG-H873) AppleWebKit\/537.36 (KH\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":254},{"id":8978529,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34760,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 249, \u0022payload_entropy\u0022: 5.399581097440054, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022889752da353cddb4ced8e68e1a4bf798\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/frontend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit\/537.36 \u0022, \u0022request_sample\u0022: \u0022GET \/frontend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/78.0.3875.0 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/frontend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit\/537.36\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/frontend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/78.0.3875.0 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/frontend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit\/537.36\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022d76cacc7b53b4e39c2f0b2c838098dd0ab19680c\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/frontend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit\/537.36\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/frontend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit\/537.36\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/frontend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit\/537.36\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/frontend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit\/537.36\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":249},{"id":8978530,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34762,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 261, \u0022payload_entropy\u0022: 5.472234650762604, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022744b4cf71da5978540eb3a8b2f3d68d4\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/private\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KHT\u0022, \u0022request_sample\u0022: \u0022GET \/private\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KHTML, like Gecko) Chrome\/11.0.696.65 Safari\/534.35 Puffin\/2.9174AP\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: clos\u0022, \u0022payload_snippet\u0022: \u0022GET \/private\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KHT\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/private\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KHTML, like Gecko) Chrome\/11.0.696.65 Safari\/534.35 Puffin\/2.9174AP\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: clos\u0022, \u0022payload_snippet\u0022: \u0022GET \/private\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KHT\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022745164956ccdf047ed587baa966bf9bab3a3ad42\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/private\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KHT\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/private\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KHT\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/private\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KHT\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/private\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KHT\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":261},{"id":8978531,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34776,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 223, \u0022payload_entropy\u0022: 5.242746132162274, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002260ff3e6d3c39606b5af0b950e91b7231\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/backend\/.env.staging HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10.6; rv:2.0.1) Ge\u0022, \u0022request_sample\u0022: \u0022GET \/backend\/.env.staging HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10.6; rv:2.0.1) Gecko\/20100101 Firefox\/4.0.1\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/backend\/.env.staging HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10.6; rv:2.0.1) Ge\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/backend\/.env.staging HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10.6; rv:2.0.1) Gecko\/20100101 Firefox\/4.0.1\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/backend\/.env.staging HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10.6; rv:2.0.1) Ge\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00227ac6b6cc2e1231b18b77ab230e0f39c34f784394\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/backend\/.env.staging HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10.6; rv:2.0.1) Ge\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/backend\/.env.staging HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10.6; rv:2.0.1) Ge\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/backend\/.env.staging HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10.6; rv:2.0.1) Ge\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/backend\/.env.staging HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10.6; rv:2.0.1) Ge\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":223},{"id":8978532,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34788,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 247, \u0022payload_entropy\u0022: 5.395213764147858, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00229dc91d9908f32ca5f0e602427d9de454\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/internal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit\/537.36 (KHT\u0022, \u0022request_sample\u0022: \u0022GET \/internal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/72.0.3626.122 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/internal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit\/537.36 (KHT\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/internal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/72.0.3626.122 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/internal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit\/537.36 (KHT\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002289ade5bd873048286f57bf6ec2db650c21380419\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/internal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit\/537.36 (KHT\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/internal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit\/537.36 (KHT\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/internal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit\/537.36 (KHT\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/internal\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit\/537.36 (KHT\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":247},{"id":8978533,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34798,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 278, \u0022payload_entropy\u0022: 5.420050032705711, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002289b2c7946137826a0a8ed5d320b60253\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/backend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/604.1 (KHTML, lik\u0022, \u0022request_sample\u0022: \u0022GET \/backend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/604.1 (KHTML, like Gecko) Version\/11.0 Safari\/604.1 Ubuntu\/17.04 (3.24.1-0ubuntu1) Epiphany\/3.24.1\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\u0022, \u0022payload_snippet\u0022: \u0022GET \/backend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/604.1 (KHTML, lik\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/backend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/604.1 (KHTML, like Gecko) Version\/11.0 Safari\/604.1 Ubuntu\/17.04 (3.24.1-0ubuntu1) Epiphany\/3.24.1\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\u0022, \u0022payload_snippet\u0022: \u0022GET \/backend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/604.1 (KHTML, lik\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022cf01e546e8d7c2772cc39b8b8cd4346f3050db26\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/backend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/604.1 (KHTML, lik\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/backend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/604.1 (KHTML, lik\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/backend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/604.1 (KHTML, lik\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/backend\/.env.dev HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/604.1 (KHTML, lik\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":278},{"id":8978534,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34820,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 231, \u0022payload_entropy\u0022: 5.283751513231423, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.9, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 34, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00224c534dfcbc4ff30ad0edf86865b3d75c7daa6ecf\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022matched_patterns\u0022: [\u0022pat-0103\u0022], \u0022matched_pattern_names\u0022: [\u0022LFI Double-dot bypass\u0022], \u0022pattern_ids\u0022: [\u0022pat-0103\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 34}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00221e99878c38b4a9741f039d6bcfc86206\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 34}, \u0022payload_preview\u0022: \u0022GET \/public\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: DoCoMo\/2.0 N905i(c100;TB;W24H16) (compatible; Googlebot-Mobile\/2.1\u0022, \u0022request_sample\u0022: \u0022GET \/public\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: DoCoMo\/2.0 N905i(c100;TB;W24H16) (compatible; Googlebot-Mobile\/2.1;  http:\/\/www.google.com\/bot.html)\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/public\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: DoCoMo\/2.0 N905i(c100;TB;W24H16) (compatible; Googlebot-Mobile\/2.1\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/public\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: DoCoMo\/2.0 N905i(c100;TB;W24H16) (compatible; Googlebot-Mobile\/2.1;  http:\/\/www.google.com\/bot.html)\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/public\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: DoCoMo\/2.0 N905i(c100;TB;W24H16) (compatible; Googlebot-Mobile\/2.1\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00228cd7c0a233d4522901b6cb086d235cbaa29ed729\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/public\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: DoCoMo\/2.0 N905i(c100;TB;W24H16) (compatible; Googlebot-Mobile\/2.1\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/public\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: DoCoMo\/2.0 N905i(c100;TB;W24H16) (compatible; Googlebot-Mobile\/2.1\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 4 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 34\/100 (Faible) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 34}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 34, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/public\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: DoCoMo\/2.0 N905i(c100;TB;W24H16) (compatible; Googlebot-Mobile\/2.1\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/public\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: DoCoMo\/2.0 N905i(c100;TB;W24H16) (compatible; Googlebot-Mobile\/2.1\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 4 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":231},{"id":8978535,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34824,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 193, \u0022payload_entropy\u0022: 5.2415145007404735, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002212e06c7fd614b292d73a27c7577c471c\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/www\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; rv:36.0) Gecko\/20100101 Firefox\/36.0\\r\\nAc\u0022, \u0022request_sample\u0022: \u0022GET \/www\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; rv:36.0) Gecko\/20100101 Firefox\/36.0\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/www\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; rv:36.0) Gecko\/20100101 Firefox\/36.0\\r\\nAc\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/www\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; rv:36.0) Gecko\/20100101 Firefox\/36.0\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/www\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; rv:36.0) Gecko\/20100101 Firefox\/36.0\\r\\nAc\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022b617a46995e43273a08f5e7d90567494e64bb722\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/www\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; rv:36.0) Gecko\/20100101 Firefox\/36.0\\r\\nAc\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/www\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; rv:36.0) Gecko\/20100101 Firefox\/36.0\\r\\nAc\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/www\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; rv:36.0) Gecko\/20100101 Firefox\/36.0\\r\\nAc\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/www\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; rv:36.0) Gecko\/20100101 Firefox\/36.0\\r\\nAc\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":193},{"id":8978536,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34812,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 259, \u0022payload_entropy\u0022: 5.441252310554823, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00220e303191d1b368abea5fa364131f82d3\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/backend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; RMX1851) AppleWebKit\/537.36\u0022, \u0022request_sample\u0022: \u0022GET \/backend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; RMX1851) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/75.0.3770.143 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\u0022, \u0022payload_snippet\u0022: \u0022GET \/backend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; RMX1851) AppleWebKit\/537.36\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/backend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; RMX1851) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/75.0.3770.143 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\u0022, \u0022payload_snippet\u0022: \u0022GET \/backend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; RMX1851) AppleWebKit\/537.36\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022508594aade06520d4182d3edcea5d26d8f513ba8\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/backend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; RMX1851) AppleWebKit\/537.36\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/backend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; RMX1851) AppleWebKit\/537.36\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/backend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; RMX1851) AppleWebKit\/537.36\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/backend\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; RMX1851) AppleWebKit\/537.36\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":259},{"id":8978537,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34852,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 265, \u0022payload_entropy\u0022: 5.40932589730829, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022e9b60034bd4e29f75a06088e2c041690\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/apps\/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KH\u0022, \u0022request_sample\u0022: \u0022GET \/apps\/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.100 Safari\/537.36 OPR\/63.0.3368.35\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: \u0022, \u0022payload_snippet\u0022: \u0022GET \/apps\/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KH\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/apps\/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.100 Safari\/537.36 OPR\/63.0.3368.35\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: \u0022, \u0022payload_snippet\u0022: \u0022GET \/apps\/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KH\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022e990b536199115094b20922b4dbf8e8bd268dd4d\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/apps\/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KH\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/apps\/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KH\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/apps\/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KH\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/apps\/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KH\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":265},{"id":8978538,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34834,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 237, \u0022payload_entropy\u0022: 5.424866744892322, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00220c22c653c6e6dcf010b4ae5410d92fb2\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/cms\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KHTML, like \u0022, \u0022request_sample\u0022: \u0022GET \/cms\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/67.0.3396.87 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/cms\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KHTML, like\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/cms\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/67.0.3396.87 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/cms\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KHTML, like\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022d952e919145dccab2ffd2f6cc65b19fbccd39565\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/cms\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KHTML, like\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/cms\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KHTML, like\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/cms\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KHTML, like\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/cms\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; WOW64) AppleWebKit\/537.36 (KHTML, like\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":237},{"id":8978539,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34844,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 255, \u0022payload_entropy\u0022: 5.436125077959244, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022d8313654f6bd314de2743ddd400d3f06\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/apps\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 7.0; FRD-L09) AppleWebKit\/537.36 (KH\u0022, \u0022request_sample\u0022: \u0022GET \/apps\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 7.0; FRD-L09) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.111 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/apps\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 7.0; FRD-L09) AppleWebKit\/537.36 (KH\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/apps\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 7.0; FRD-L09) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.111 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/apps\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 7.0; FRD-L09) AppleWebKit\/537.36 (KH\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002271944678b92908c8eb092b2931f1ac620842eeb3\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/apps\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 7.0; FRD-L09) AppleWebKit\/537.36 (KH\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/apps\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 7.0; FRD-L09) AppleWebKit\/537.36 (KH\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/apps\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 7.0; FRD-L09) AppleWebKit\/537.36 (KH\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/apps\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 7.0; FRD-L09) AppleWebKit\/537.36 (KH\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":255},{"id":8978540,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34868,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 304, \u0022payload_entropy\u0022: 5.263245145488292, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002287a9ffcb2dc380ee03acfa48709b2cef\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\/4.0; \u0022, \u0022request_sample\u0022: \u0022GET \/sendgrid\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)\\r\\nAccept-Charset: utf\u0022, \u0022payload_snippet\u0022: \u0022GET \/sendgrid\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\/4.0;\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/sendgrid\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)\\r\\nAccept-Charset: utf\u0022, \u0022payload_snippet\u0022: \u0022GET \/sendgrid\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\/4.0;\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022928798301954790128d5eb57e30182fa8822b06c\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\/4.0;\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/sendgrid\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\/4.0;\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\/4.0;\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/sendgrid\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\/4.0;\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":304},{"id":8978541,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34880,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 253, \u0022payload_entropy\u0022: 5.406619974156834, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022b7c070ac76ac533fa6a0484055753204\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/.sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; CLT-L29) AppleWebKit\/537.36 (KHTM\u0022, \u0022request_sample\u0022: \u0022GET \/.sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; CLT-L29) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.111 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/.sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; CLT-L29) AppleWebKit\/537.36 (KHTM\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/.sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; CLT-L29) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.111 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/.sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; CLT-L29) AppleWebKit\/537.36 (KHTM\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002244684a3e8a16ae087ba263770a453d5ba5933bf4\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/.sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; CLT-L29) AppleWebKit\/537.36 (KHTM\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/.sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; CLT-L29) AppleWebKit\/537.36 (KHTM\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/.sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; CLT-L29) AppleWebKit\/537.36 (KHTM\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/.sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; CLT-L29) AppleWebKit\/537.36 (KHTM\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":253},{"id":8978542,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34890,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 252, \u0022payload_entropy\u0022: 5.4247121526352355, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00224c137fcc0154dcebf524bac545eeaa94\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; COL-L29) AppleWebKit\/537.36 (KHTML\u0022, \u0022request_sample\u0022: \u0022GET \/sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; COL-L29) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.111 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; COL-L29) AppleWebKit\/537.36 (KHTML\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; COL-L29) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.111 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; COL-L29) AppleWebKit\/537.36 (KHTML\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022c52795750eb0cb0c95bac2d6f9441ef2cd4b0a91\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; COL-L29) AppleWebKit\/537.36 (KHTML\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; COL-L29) AppleWebKit\/537.36 (KHTML\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; COL-L29) AppleWebKit\/537.36 (KHTML\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/sendgrid.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; COL-L29) AppleWebKit\/537.36 (KHTML\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":252},{"id":8978543,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34916,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 257, \u0022payload_entropy\u0022: 5.401506613484634, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022351c93db33df454b0ac2b64afbd7f4a5\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\u0022, \u0022request_sample\u0022: \u0022GET \/sendgrid\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/78.0.3880.4 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\u0022, \u0022payload_snippet\u0022: \u0022GET \/sendgrid\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/sendgrid\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/78.0.3880.4 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\u0022, \u0022payload_snippet\u0022: \u0022GET \/sendgrid\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00221553ac94955dc10e1f6648f4ce167b0d4dea9cb7\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/sendgrid\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/sendgrid\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":257},{"id":8978544,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34904,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 255, \u0022payload_entropy\u0022: 5.418660243130461, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022d036da1a8a9b3528399cd2780dcdf151\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/dashboard\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit\/537\u0022, \u0022request_sample\u0022: \u0022GET \/dashboard\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/73.0.3683.103 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/dashboard\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit\/537\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/dashboard\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/73.0.3683.103 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/dashboard\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit\/537\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022fa158a79fd5f7c25b4ad8e660c0ed2990173dd90\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/dashboard\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit\/537\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/dashboard\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit\/537\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/dashboard\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit\/537\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/dashboard\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit\/537\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":255},{"id":8978545,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34982,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 231, \u0022payload_entropy\u0022: 5.394467465313376, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022a4f8a08a41133c36e4e6d31a2e875ca1\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/tmp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0) AppleWebKit\/537.36 (KHTML, like Gecko) \u0022, \u0022request_sample\u0022: \u0022GET \/tmp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/74.0.3729.157 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/tmp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0) AppleWebKit\/537.36 (KHTML, like Gecko)\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/tmp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/74.0.3729.157 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/tmp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0) AppleWebKit\/537.36 (KHTML, like Gecko)\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022bb16787334ace3c8e36ae5f1eeb89e4f8cfb9be0\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/tmp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0) AppleWebKit\/537.36 (KHTML, like Gecko)\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/tmp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0) AppleWebKit\/537.36 (KHTML, like Gecko)\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/tmp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0) AppleWebKit\/537.36 (KHTML, like Gecko)\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/tmp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0) AppleWebKit\/537.36 (KHTML, like Gecko)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":231},{"id":8978546,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34984,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 262, \u0022payload_entropy\u0022: 5.465599624198988, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022522d381593af34cccfe1b46290ce77fd\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KH\u0022, \u0022request_sample\u0022: \u0022GET \/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KHTML, like Gecko) Chrome\/11.0.696.65 Safari\/534.35 Puffin\/2.9174AP\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: clo\u0022, \u0022payload_snippet\u0022: \u0022GET \/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KH\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KHTML, like Gecko) Chrome\/11.0.696.65 Safari\/534.35 Puffin\/2.9174AP\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: clo\u0022, \u0022payload_snippet\u0022: \u0022GET \/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KH\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002258e44892ba63383b397290b9ab82cf0239b44ee0\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KH\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KH\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KH\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/frontend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; U; Linux x86_64; en-gb) AppleWebKit\/534.35 (KH\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":262},{"id":8978547,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":35020,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 221, \u0022payload_entropy\u0022: 5.309181386890489, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 34, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00220f22d3d03ed2592133d8266d34dad6c22eaf89eb\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 34}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022d99aa18f09f25242f2383d2abbd4ba4f\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 34}, \u0022payload_preview\u0022: \u0022GET \/backend\/.env.bak HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: MOT-L7v\/08.B7.5DR MIB\/2.2.1 Profile\/MIDP-2.0 Configuration\/CL\u0022, \u0022request_sample\u0022: \u0022GET \/backend\/.env.bak HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: MOT-L7v\/08.B7.5DR MIB\/2.2.1 Profile\/MIDP-2.0 Configuration\/CLDC-1.1 UP.Link\/6.3.0.0.0\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/backend\/.env.bak HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: MOT-L7v\/08.B7.5DR MIB\/2.2.1 Profile\/MIDP-2.0 Configuration\/CL\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/backend\/.env.bak HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: MOT-L7v\/08.B7.5DR MIB\/2.2.1 Profile\/MIDP-2.0 Configuration\/CLDC-1.1 UP.Link\/6.3.0.0.0\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/backend\/.env.bak HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: MOT-L7v\/08.B7.5DR MIB\/2.2.1 Profile\/MIDP-2.0 Configuration\/CL\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022af332cedd2ecf17ea56feeb7fab1a1b7a2194edf\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/backend\/.env.bak HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: MOT-L7v\/08.B7.5DR MIB\/2.2.1 Profile\/MIDP-2.0 Configuration\/CL\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/backend\/.env.bak HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: MOT-L7v\/08.B7.5DR MIB\/2.2.1 Profile\/MIDP-2.0 Configuration\/CL\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 34\/100 (Faible) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 34}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 34, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/backend\/.env.bak HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: MOT-L7v\/08.B7.5DR MIB\/2.2.1 Profile\/MIDP-2.0 Configuration\/CL\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/backend\/.env.bak HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: MOT-L7v\/08.B7.5DR MIB\/2.2.1 Profile\/MIDP-2.0 Configuration\/CL\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022net_flood\u0022, \u0022redis_config_probe\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022net_flood\u0022, \u0022redis_config_probe\u0022]","anomalies":"[]","severity":7,"bytes_in":221},{"id":8978548,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":35014,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 233, \u0022payload_entropy\u0022: 5.431943481888588, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022aadef01f210e2cfe19be3818e725dfdf\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/wp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; WOW64) AppleWebKit\/534.27 (KHTML, like Ge\u0022, \u0022request_sample\u0022: \u0022GET \/wp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; WOW64) AppleWebKit\/534.27 (KHTML, like Gecko) Chrome\/12.0.712.0 Safari\/534.27\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/wp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; WOW64) AppleWebKit\/534.27 (KHTML, like Ge\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/wp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; WOW64) AppleWebKit\/534.27 (KHTML, like Gecko) Chrome\/12.0.712.0 Safari\/534.27\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/wp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; WOW64) AppleWebKit\/534.27 (KHTML, like Ge\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022500a5569d7c7a65c971ac047ed70b40716972df2\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/wp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; WOW64) AppleWebKit\/534.27 (KHTML, like Ge\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/wp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; WOW64) AppleWebKit\/534.27 (KHTML, like Ge\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/wp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; WOW64) AppleWebKit\/534.27 (KHTML, like Ge\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/wp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; WOW64) AppleWebKit\/534.27 (KHTML, like Ge\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":233},{"id":8978549,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34998,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 238, \u0022payload_entropy\u0022: 5.4713474988111015, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002201b23c6d4fd1e67206adb2d5014f44cd\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/wordpress\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like\u0022, \u0022request_sample\u0022: \u0022GET \/wordpress\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/56.0.2924.76 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/wordpress\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/wordpress\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/56.0.2924.76 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/wordpress\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022feb55313d08e336f4b3a87c98de66e6c528b733e\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/wordpress\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/wordpress\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/wordpress\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/wordpress\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":238},{"id":8978550,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34938,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 274, \u0022payload_entropy\u0022: 5.3450830109555145, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022dd64713381702b30f03c1340cc7ca940\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 10_3_3 like Mac OS X) A\u0022, \u0022request_sample\u0022: \u0022GET \/sendgrid\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 10_3_3 like Mac OS X) AppleWebKit\/603.3.8 (KHTML, like Gecko) Version\/10.0 Mobile\/14G60 Safari\/602.1\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nCon\u0022, \u0022payload_snippet\u0022: \u0022GET \/sendgrid\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 10_3_3 like Mac OS X) A\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/sendgrid\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 10_3_3 like Mac OS X) AppleWebKit\/603.3.8 (KHTML, like Gecko) Version\/10.0 Mobile\/14G60 Safari\/602.1\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nCon\u0022, \u0022payload_snippet\u0022: \u0022GET \/sendgrid\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 10_3_3 like Mac OS X) A\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022cb7761cdc7a2232cd18d96795987ceedba8898c2\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 10_3_3 like Mac OS X) A\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/sendgrid\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 10_3_3 like Mac OS X) A\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 10_3_3 like Mac OS X) A\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/sendgrid\/.env.local HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (iPhone; CPU iPhone OS 10_3_3 like Mac OS X) A\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":274},{"id":8978551,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34972,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 280, \u0022payload_entropy\u0022: 5.3936605960686625, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002255de0445f56034ece44eb3ef4075a06f\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/temp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 1.5; en-gb; T-Mobile_G2_Touch Build\/C\u0022, \u0022request_sample\u0022: \u0022GET \/temp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 1.5; en-gb; T-Mobile_G2_Touch Build\/CUPCAKE) AppleWebKit\/528.5  (KHTML, like Gecko) Version\/3.1.2 Mobile Safari\/525.20.1\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzi\u0022, \u0022payload_snippet\u0022: \u0022GET \/temp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 1.5; en-gb; T-Mobile_G2_Touch Build\/C\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/temp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 1.5; en-gb; T-Mobile_G2_Touch Build\/CUPCAKE) AppleWebKit\/528.5  (KHTML, like Gecko) Version\/3.1.2 Mobile Safari\/525.20.1\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzi\u0022, \u0022payload_snippet\u0022: \u0022GET \/temp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 1.5; en-gb; T-Mobile_G2_Touch Build\/C\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00224bd60511ec7691e49d8cacf715be96e2eb525f9c\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/temp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 1.5; en-gb; T-Mobile_G2_Touch Build\/C\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/temp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 1.5; en-gb; T-Mobile_G2_Touch Build\/C\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/temp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 1.5; en-gb; T-Mobile_G2_Touch Build\/C\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/temp\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 1.5; en-gb; T-Mobile_G2_Touch Build\/C\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":280},{"id":8978552,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34954,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 261, \u0022payload_entropy\u0022: 5.384510452365788, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00228828a9c88ab819556b2fc441d0293620\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/apps\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-US) App\u0022, \u0022request_sample\u0022: \u0022GET \/apps\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-US) AppleWebKit\/532.8 (KHTML, like Gecko) Chrome\/4.0.302.2 Safari\/532.8\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: clos\u0022, \u0022payload_snippet\u0022: \u0022GET \/apps\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-US) App\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/apps\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-US) AppleWebKit\/532.8 (KHTML, like Gecko) Chrome\/4.0.302.2 Safari\/532.8\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: clos\u0022, \u0022payload_snippet\u0022: \u0022GET \/apps\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-US) App\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002246b8cac5e76f1f9fb0a0e8ca570d623a67375fc9\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/apps\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-US) App\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/apps\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-US) App\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/apps\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-US) App\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/apps\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-US) App\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":261},{"id":8978553,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34956,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 261, \u0022payload_entropy\u0022: 5.43629794155099, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022639f2d6925d7b43acc3129f2a81e3249\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960F) AppleWebKit\/537.\u0022, \u0022request_sample\u0022: \u0022GET \/sendgrid\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960F) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.111 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: clos\u0022, \u0022payload_snippet\u0022: \u0022GET \/sendgrid\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960F) AppleWebKit\/537.\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/sendgrid\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960F) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.111 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: clos\u0022, \u0022payload_snippet\u0022: \u0022GET \/sendgrid\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960F) AppleWebKit\/537.\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022a9e8050a3aafb522cc0ecbb6e1ee44400567cd06\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960F) AppleWebKit\/537.\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/sendgrid\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960F) AppleWebKit\/537.\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960F) AppleWebKit\/537.\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/sendgrid\/.env.backup HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G960F) AppleWebKit\/537.\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":261},{"id":8978554,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":34924,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 206, \u0022payload_entropy\u0022: 5.282357695629701, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00224bdd6597dc0b7e40e102ab8f16b28141\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:38.0) Gecko\/20100101 Fir\u0022, \u0022request_sample\u0022: \u0022GET \/sendgrid\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:38.0) Gecko\/20100101 Firefox\/38.0\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/sendgrid\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:38.0) Gecko\/20100101 Fir\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/sendgrid\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:38.0) Gecko\/20100101 Firefox\/38.0\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/sendgrid\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:38.0) Gecko\/20100101 Fir\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022299c4049ecc6193a1c5dcb52055329e21ec4c3d0\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:38.0) Gecko\/20100101 Fir\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/sendgrid\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:38.0) Gecko\/20100101 Fir\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/sendgrid\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:38.0) Gecko\/20100101 Fir\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/sendgrid\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:38.0) Gecko\/20100101 Fir\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":206},{"id":8978555,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":35030,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 263, \u0022payload_entropy\u0022: 5.399717065529561, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002269d006755771d2630c732381d1130ea7\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/backend\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.1.0; LM-Q710.FG) AppleWebKit\/53\u0022, \u0022request_sample\u0022: \u0022GET \/backend\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.1.0; LM-Q710.FG) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/75.0.3770.101 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: cl\u0022, \u0022payload_snippet\u0022: \u0022GET \/backend\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.1.0; LM-Q710.FG) AppleWebKit\/53\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/backend\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.1.0; LM-Q710.FG) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/75.0.3770.101 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: cl\u0022, \u0022payload_snippet\u0022: \u0022GET \/backend\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.1.0; LM-Q710.FG) AppleWebKit\/53\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022cae8d00cdca7fa3c5b07ff66939c45b221468862\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/backend\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.1.0; LM-Q710.FG) AppleWebKit\/53\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/backend\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.1.0; LM-Q710.FG) AppleWebKit\/53\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/backend\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.1.0; LM-Q710.FG) AppleWebKit\/53\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/backend\/api\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 8.1.0; LM-Q710.FG) AppleWebKit\/53\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":263},{"id":8978556,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":35042,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 258, \u0022payload_entropy\u0022: 5.372589524800817, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022de5dfc3a4c1151572aab43feb1240a89\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/backend\/.env.old HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 4.1; en-us; sdk Build\/MR1) App\u0022, \u0022request_sample\u0022: \u0022GET \/backend\/.env.old HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 4.1; en-us; sdk Build\/MR1) AppleWebKit\/534.30 (KHTML, like Gecko) Version\/4.1 Safari\/534.30\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/backend\/.env.old HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 4.1; en-us; sdk Build\/MR1) App\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/backend\/.env.old HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 4.1; en-us; sdk Build\/MR1) AppleWebKit\/534.30 (KHTML, like Gecko) Version\/4.1 Safari\/534.30\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/backend\/.env.old HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 4.1; en-us; sdk Build\/MR1) App\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002254b3d59ba198be7de14e4367fde745024e3a0200\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/backend\/.env.old HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 4.1; en-us; sdk Build\/MR1) App\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/backend\/.env.old HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 4.1; en-us; sdk Build\/MR1) App\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/backend\/.env.old HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 4.1; en-us; sdk Build\/MR1) App\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/backend\/.env.old HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; U; Android 4.1; en-us; sdk Build\/MR1) App\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":258},{"id":8978557,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":35064,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 241, \u0022payload_entropy\u0022: 5.446138390440651, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022af6c3b66cfac584de5b81d8e8546331a\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/symfony\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.36 (KHTML, li\u0022, \u0022request_sample\u0022: \u0022GET \/symfony\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.100 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/symfony\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.36 (KHTML, li\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/symfony\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.100 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/symfony\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.36 (KHTML, li\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022f5a471d640149614f94b09126ee8618edfef3894\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/symfony\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.36 (KHTML, li\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/symfony\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.36 (KHTML, li\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/symfony\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.36 (KHTML, li\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/symfony\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.36 (KHTML, li\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":241},{"id":8978558,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":35050,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 253, \u0022payload_entropy\u0022: 5.398476599728502, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022b75123fe1227fac2bd36489cc8a26973\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/frontend\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.3\u0022, \u0022request_sample\u0022: \u0022GET \/frontend\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.100 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/frontend\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.3\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/frontend\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.100 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/frontend\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.3\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022add65a07071fba74328672f9210c614b41231742\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/frontend\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.3\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/frontend\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.3\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/frontend\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.3\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/frontend\/.env.production HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 6.3; WOW64) AppleWebKit\/537.3\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":253},{"id":8978559,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":35090,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 239, \u0022payload_entropy\u0022: 5.325012347532088, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022c4ef51ce64ecd1073c5372b949ab74d8\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/html\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (Windows; U; MSIE 7.0; Windows NT 6.0; .NET CLR 1.0.4072\u0022, \u0022request_sample\u0022: \u0022GET \/html\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (Windows; U; MSIE 7.0; Windows NT 6.0; .NET CLR 1.0.40727; Media Center PC 4.0; InfoPath.1; en-NZ)\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/html\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (Windows; U; MSIE 7.0; Windows NT 6.0; .NET CLR 1.0.4072\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/html\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (Windows; U; MSIE 7.0; Windows NT 6.0; .NET CLR 1.0.40727; Media Center PC 4.0; InfoPath.1; en-NZ)\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/html\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (Windows; U; MSIE 7.0; Windows NT 6.0; .NET CLR 1.0.4072\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022d89c866cc6b3e5009e2553a22a950be196b7cc95\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/html\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (Windows; U; MSIE 7.0; Windows NT 6.0; .NET CLR 1.0.4072\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/html\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (Windows; U; MSIE 7.0; Windows NT 6.0; .NET CLR 1.0.4072\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/html\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (Windows; U; MSIE 7.0; Windows NT 6.0; .NET CLR 1.0.4072\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/html\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/4.0 (Windows; U; MSIE 7.0; Windows NT 6.0; .NET CLR 1.0.4072\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":239},{"id":8978560,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":35100,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 215, \u0022payload_entropy\u0022: 5.410518751959478, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00226a237549be1c30fdb9f27eb96b5f832d\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/htdocs\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (SymbianOS\/9.1; U; en-us) AppleWebKit\/413 (KHTML, like\u0022, \u0022request_sample\u0022: \u0022GET \/htdocs\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (SymbianOS\/9.1; U; en-us) AppleWebKit\/413 (KHTML, like Gecko) Safari\/413\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/htdocs\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (SymbianOS\/9.1; U; en-us) AppleWebKit\/413 (KHTML, like\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/htdocs\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (SymbianOS\/9.1; U; en-us) AppleWebKit\/413 (KHTML, like Gecko) Safari\/413\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/htdocs\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (SymbianOS\/9.1; U; en-us) AppleWebKit\/413 (KHTML, like\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002226fd6caef8ca884bec26df32785c9580f746281a\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/htdocs\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (SymbianOS\/9.1; U; en-us) AppleWebKit\/413 (KHTML, like\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/htdocs\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (SymbianOS\/9.1; U; en-us) AppleWebKit\/413 (KHTML, like\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/htdocs\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (SymbianOS\/9.1; U; en-us) AppleWebKit\/413 (KHTML, like\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/htdocs\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (SymbianOS\/9.1; U; en-us) AppleWebKit\/413 (KHTML, like\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":215},{"id":8978562,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":35080,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 141, \u0022payload_entropy\u0022: 5.09303758762464, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.9, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 34, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00224c534dfcbc4ff30ad0edf86865b3d75c7daa6ecf\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 34}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022507ae1115f720f65bd09d69c49d9686a\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 34}, \u0022payload_preview\u0022: \u0022GET \/web\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: P3P Validator\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnecti\u0022, \u0022request_sample\u0022: \u0022GET \/web\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: P3P Validator\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/web\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: P3P Validator\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnecti\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/web\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: P3P Validator\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/web\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: P3P Validator\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnecti\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022a9a994db55ebca3f0b0e0d90ae87a495810d16b1\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/web\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: P3P Validator\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnecti\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/web\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: P3P Validator\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnecti\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 4 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 34\/100 (Faible) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 34}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 34, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/web\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: P3P Validator\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnecti\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/web\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: P3P Validator\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnecti\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 4 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":141},{"id":8978564,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":35114,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 258, \u0022payload_entropy\u0022: 5.423949699636017, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00225559f2eb08a941d4f667141d64275d4d\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/frontend\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_2) AppleWebKit\u0022, \u0022request_sample\u0022: \u0022GET \/frontend\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_2) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.84 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/frontend\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_2) AppleWebKit\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/frontend\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_2) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/76.0.3809.84 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/frontend\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_2) AppleWebKit\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002248bd1f052e8b0a66897d0f25e751e118177d8a51\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/frontend\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_2) AppleWebKit\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/frontend\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_2) AppleWebKit\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/frontend\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_2) AppleWebKit\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/frontend\/.env.prod HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_14_2) AppleWebKit\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":258},{"id":8978567,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":35124,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 270, \u0022payload_entropy\u0022: 5.468662634708652, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00220b4ba6ffd0ecc702b62df5441063e986\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/uploads\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; LEX829) AppleWebKit\/537.36 (KHTML,\u0022, \u0022request_sample\u0022: \u0022GET \/uploads\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; LEX829) AppleWebKit\/537.36 (KHTML, like Gecko) SamsungBrowser\/10.1 Chrome\/71.0.3578.99 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnect\u0022, \u0022payload_snippet\u0022: \u0022GET \/uploads\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; LEX829) AppleWebKit\/537.36 (KHTML,\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/uploads\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; LEX829) AppleWebKit\/537.36 (KHTML, like Gecko) SamsungBrowser\/10.1 Chrome\/71.0.3578.99 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnect\u0022, \u0022payload_snippet\u0022: \u0022GET \/uploads\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; LEX829) AppleWebKit\/537.36 (KHTML,\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00221543cb3d6d6269c9416c91ad43a343a125f7b778\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/uploads\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; LEX829) AppleWebKit\/537.36 (KHTML,\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/uploads\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; LEX829) AppleWebKit\/537.36 (KHTML,\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/uploads\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; LEX829) AppleWebKit\/537.36 (KHTML,\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/uploads\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; LEX829) AppleWebKit\/537.36 (KHTML,\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":270},{"id":8978568,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":35126,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 262, \u0022payload_entropy\u0022: 5.417424098660095, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022c25be046f81fb873881b52d6972d4864\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/services\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G965F) AppleWebKit\/537\u0022, \u0022request_sample\u0022: \u0022GET \/services\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G965F) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/75.0.3770.101 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: clo\u0022, \u0022payload_snippet\u0022: \u0022GET \/services\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G965F) AppleWebKit\/537\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/services\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G965F) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/75.0.3770.101 Mobile Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: clo\u0022, \u0022payload_snippet\u0022: \u0022GET \/services\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G965F) AppleWebKit\/537\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00222b078de4a913223c4d653c5e0455bb07f0670fc0\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/services\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G965F) AppleWebKit\/537\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/services\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G965F) AppleWebKit\/537\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/services\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G965F) AppleWebKit\/537\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/services\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Linux; Android 9; SM-G965F) AppleWebKit\/537\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":262},{"id":8978569,"ip":"34.47.80.115","ts":"2026-06-14 18:05:32.000000","proto":"tcp","src_port":35146,"dst_port":8020,"service":"hdfs-namenode","classification":"syn_flood","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a436f6e74656e742d4c656e6774683a2037330d0a0d0a7b2270726f746f636f6c223a226f72672e6170616368652e6861646f6f702e686466732e70726f746f636f6c2e436c69656e7450726f746f63\u0022, \u0022emulator_response_len\u0022: 144, \u0022bytes_in\u0022: 250, \u0022payload_entropy\u0022: 5.41003651399878, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022app_proto\u0022: \u0022hdfs-namenode\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022KR\u0022, \u0022dst_port\u0022: 8020, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 79.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 20, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 43, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002225e80c7c0b4884fc729d9130b735ffc00ad5a6a9\u0022, \u0022event_fingerprint\u0022: \u0022004499a144c92e4455aac1722fd9719117630099\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022confidence\u0022: 0.0, \u0022classification_confidence\u0022: 0.0, \u0022precision_score\u0022: 0, \u0022precision_signals\u0022: [], \u0022kb_rule_ids\u0022: [], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_confidence_factor\u0022: 0.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022KR\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022f15d575621dd43b3958b38f7ed7f6543\u0022, \u0022path_pattern_hash\u0022: \u002218ea0213c0d23e39dd8461c4478348f1\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022risk_score\u0022: 43}, \u0022payload_preview\u0022: \u0022GET \/api\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 \u0022, \u0022request_sample\u0022: \u0022GET \/api\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/75.0.3770.80 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/api\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022GET \/api\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/75.0.3770.80 Safari\/537.36\\r\\nAccept-Charset: utf-8\\r\\nAccept-Encoding: gzip\\r\\nConnection: close\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/api\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022ddos\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002268594f1a6d5ac954f79b3824572355331da3f323\u0022, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/api\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/api\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36\u0022, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab syn_flood \u00bb (signaux protocolaires) \u00b7 confiance 0%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 43\/100 (Moyen) \u2014 MITRE TA0001 \u2014 via HDFS NAMENODE\u0022, \u0022confidence_pct\u0022: 0, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 79.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 43}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 43, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022, \u0022dst_port\u0022: 8020, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: null, \u0022tags_summary_labels_fr\u0022: null, \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022payload_preview\u0022: \u0022GET \/api\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36\u0022, \u0022port\u0022: 8020, \u0022service\u0022: \u0022hdfs-namenode\u0022, \u0022service_label_fr\u0022: \u0022HDFS NAMENODE\u0022}, \u0022attack_vector\u0022: \u0022syn flood \u00b7 via HDFS NAMENODE:8020 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/api\/backend\/.env HTTP\/1.1\\r\\nHost: 62.3.50.33:8020\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36\u0022, \u0022target_port_label\u0022: \u00228020 \u00b7 HDFS NAMENODE\u0022, \u0022emulator_service\u0022: \u0022hdfs-namenode\u0022, \u0022confidence_reason\u0022: \u0022Confiance 0 % \u2014 5 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: null, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022hdfs_namenode\u0022, \u0022service_banner\u0022: \u0022honeypot-hdfs-namenode\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228020\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022hdfs_namenode_emulated\u0022, \u0022hdfs_namenode_payload\u0022, \u0022http_get_probe\u0022, \u0022mozi_pattern\u0022, \u0022net_flood\u0022]","anomalies":"[]","severity":7,"bytes_in":250}],"total_events":332}