{"ip":"34.76.60.10","exported_at":"2026-06-16T03:15:48+00:00","period_days":7,"metrics":{"events7d":287,"distinct_ports":219,"distinct_classifications":199,"max_severity":8,"last_sensor_id":"paris-1","max_waf_score":16,"max_risk_score":63,"attack_stage":"exploit_attempt","attack_chain_stage":"exploitation","threat_family":["unknown"],"recommended_action":"investigate","confidence":0.62,"risk_breakdown":{"waf":72,"classification":72,"behavior":0,"geo":40,"protocol":40,"novelty":15},"mitre_tactics":["TA0001","TA0002"],"mitre_technique":"TA0001","top_mitre_technique":"TA0007","top_mitre_count":208,"executive_one_liner_fr":"Activit\u00e9 suspecte \u2014 risque 53\/100 (Moyen) \u2014 MITRE TA0001 \u2014 confiance 62 % \u2014 via ELASTICSEARCH","campaign_hint_fr":null,"confidence_breakdown":{"waf":72,"classification":72,"behavior":0,"geo":40,"protocol":40,"novelty":15,"risk_score":53},"persona_hostname":"mail.sensor-1.internal","correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":62,"confidence_hint_fr":null,"sensor_role_label_fr":"Renseignement menaces","tags_summary_labels_fr":["MITRE-T1190"],"tags_summary":["MITRE-T1190"],"attack_vector":"exploit attempt \u00b7 via ELASTICSEARCH:9200 \u00b7 (tentative d\u0027exploit)","protocol_details":{"http_method":"GET","http_path":"\/","request_line":"GET \/ HTTP\/1.1","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0","elasticsearch_probe_fr":"Requ\u00eate Elasticsearch : \/","port":9200,"service":"elasticsearch","service_label_fr":"ELASTICSEARCH"},"protocol_summary_fr":"GET \/ \u00b7 UA Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20\u2026 \u00b7 ELASTICSEARCH:9200","evidence_snippet":"GET \/ HTTP\/1.1\r\nHost: 62.3.50.33:9200\r\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0\r\nAccept: *","target_port_label":"9200 \u00b7 ELASTICSEARCH","emulator_service":"elasticsearch","confidence_reason":"Confiance 62 % \u2014 3 tag(s) WAF","classification_reason":"Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%","classification_reason_label_fr":"Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%","confidence_factors_fr":"Confiance 62 % \u2014 Score WAF 72 \u00b7 3 tag(s) WAF","payload_preview":"GET \/ HTTP\/1.1\r\nHost: 62.3.50.33:9200\r\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0\r\nAccept: *"},"events":[{"id":9322189,"ip":"34.76.60.10","ts":"2026-06-15 22:27:31.000000","proto":"tcp","src_port":32912,"dst_port":9200,"service":"elasticsearch","classification":"exploit_attempt","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u0022485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6a736f6e0d0a582d656c61737469632d70726f647563743a20456c61737469637365617263680d0a436f6e74656e742d4c656e6774683a2034380d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a7b22636c\u0022, \u0022emulator_response_len\u0022: 172, \u0022http_header_count\u0022: 3, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022690a2121ff3884b792e73e436937b8ffec5ff603\u0022, \u0022http_host_hash\u0022: \u0022d19a1b8472adabca1ee6e310101ca46b45ece34e\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 134, \u0022payload_entropy\u0022: 5.154297024697998, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022elasticsearch\u0022, \u0022app_proto\u0022: \u0022elasticsearch\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 9200, \u0022risk_waf\u0022: 72.0, \u0022risk_classification\u0022: 72.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 40.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 5.2, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 53, \u0022tag_count\u0022: 4, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00221588160a3e3161f8047fceed07bc1754ee5a47dd\u0022, \u0022event_fingerprint\u0022: \u00229fad56c821c1c5ddd2cc50fc2ca67d9c1727e39e\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022confidence\u0022: 0.62, \u0022classification_confidence\u0022: 0.62, \u0022precision_score\u0022: 73, \u0022precision_signals\u0022: [\u0022MITRE-T1190\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1190\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 53}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022elasticsearch\u0022, \u0022risk_confidence_factor\u0022: 62.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022f4dce294ae88e22801a172c8ef9c5026\u0022, \u0022payload_hash\u0022: \u00226fed665a03a9d08ab9fd8229554cb6f8\u0022, \u0022path_pattern_hash\u0022: \u00228a5edab282632443219e051e4ade2d1d\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 9200, \u0022service\u0022: \u0022elasticsearch\u0022, \u0022service_name\u0022: \u0022elasticsearch\u0022, \u0022risk_score\u0022: 53}, \u0022payload_preview\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9200\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0\\r\\nAccept: *\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9200\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0\\r\\nAccept: *\/*\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9200\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0\\r\\nAccept: *\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/\u0022, \u0022user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0\u0022, \u0022waf_tags\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022], \u0022waf_rule_names\u0022: [\u0022rce-0\u0022, \u0022nosqli-3\u0022, \u0022sap-sapcontrol-path\u0022], \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9200\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0\\r\\nAccept: *\/*\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9200\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0\\r\\nAccept: *\u0022, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022mitre_tactics\u0022: [\u0022TA0001\u0022, \u0022TA0002\u0022], \u0022mitre\u0022: \u0022TA0001\u0022, \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022investigate\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022070f8886f1cae2e7a494f164e0a52251687741d3\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/\u0022, \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0\u0022, \u0022elasticsearch_probe_fr\u0022: \u0022Requ\u00eate Elasticsearch : \/\u0022, \u0022port\u0022: 9200, \u0022service\u0022: \u0022elasticsearch\u0022, \u0022service_label_fr\u0022: \u0022ELASTICSEARCH\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9200\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0\\r\\nAccept: *\u0022, \u0022attack_vector\u0022: \u0022exploit attempt \u00b7 via ELASTICSEARCH:9200 \u00b7 (tentative d\u0027exploit)\u0022, \u0022target_port_label\u0022: \u00229200 \u00b7 ELASTICSEARCH\u0022, \u0022emulator_service\u0022: \u0022elasticsearch\u0022, \u0022confidence_reason\u0022: \u0022Confiance 62 % \u2014 3 tag(s) WAF\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Tentative d\u0027exploit (tag rce-0) \u00b7 confiance 62%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 53\/100 (Moyen) \u2014 MITRE TA0001 \u2014 confiance 62 % \u2014 via ELASTICSEARCH\u0022, \u0022confidence_pct\u0022: 62, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 72.0, \u0022classification\u0022: 72.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 40.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 53}, \u0022attack_stage\u0022: \u0022exploit_attempt\u0022, \u0022attack_stage_label\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Exploitation\u0022, \u0022risk_score\u0022: 53, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022elasticsearch\u0022, \u0022service_label_fr\u0022: \u0022ELASTICSEARCH\u0022, \u0022dst_port\u0022: 9200, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022MITRE-T1190\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022MITRE-T1190\u0022], \u0022recommended_action\u0022: \u0022investigate\u0022, \u0022recommended_action_label\u0022: \u0022Investiguer\u0022, \u0022mitre\u0022: \u0022TA0001\u0022, \u0022mitre_technique\u0022: \u0022TA0001\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022Elasticsearch 8.11\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/\u0022, \u0022request_line\u0022: \u0022GET \/ HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0\u0022, \u0022elasticsearch_probe_fr\u0022: \u0022Requ\u00eate Elasticsearch : \/\u0022, \u0022port\u0022: 9200, \u0022service\u0022: \u0022elasticsearch\u0022, \u0022service_label_fr\u0022: \u0022ELASTICSEARCH\u0022}, \u0022attack_vector\u0022: \u0022exploit attempt \u00b7 via ELASTICSEARCH:9200 \u00b7 (tentative d\u0027exploit)\u0022, \u0022evidence_snippet\u0022: \u0022GET \/ HTTP\/1.1\\r\\nHost: 62.3.50.33:9200\\r\\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0\\r\\nAccept: *\u0022, \u0022target_port_label\u0022: \u00229200 \u00b7 ELASTICSEARCH\u0022, \u0022emulator_service\u0022: \u0022elasticsearch\u0022, \u0022confidence_reason\u0022: \u0022Confiance 62 % \u2014 3 tag(s) WAF\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 62 % \u2014 Score WAF 72 \u00b7 3 tag(s) WAF\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploitation\u0022, \u0022label_fr\u0022: \u0022Exploitation\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022elasticsearch\u0022, \u0022service_banner\u0022: \u0022Elasticsearch 8.11\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00229200\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022exploitation\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_investigate\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022net_elasticsearch_probe\u0022], \u0022asn_dc_heuristic\u0022: true, \u0022behavior_alert_count\u0022: 1, \u0022behavior_priority\u0022: 72}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:9200","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; rv:68.0) Gecko\/20100101 Firefox\/68.0","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022net_elasticsearch_probe\u0022]","anomalies":"[]","severity":8,"bytes_in":134},{"id":9307455,"ip":"34.76.60.10","ts":"2026-06-15 21:33:01.000000","proto":"tcp","src_port":44276,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.659457633828443, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002244160115fa5f51381a0f97377d50b6e5\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000r\ufffd^C\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000r\ufffd^C\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000r\ufffd^C\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00221c52fe44d3d51f0ad5ab360a2ab99f99697d5834\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000r\ufffd^C\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:r\ufffd^C\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000r\ufffd^C\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:r\ufffd^C\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307456,"ip":"34.76.60.10","ts":"2026-06-15 21:33:01.000000","proto":"tcp","src_port":44282,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00220c2f99c5272da9589f82818cd0cd7ebc\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd7\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd7\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd7\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022360491f7e2e48b7213569e8cdb9e5f9c5be985fa\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd7\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffd\ufffd7\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd7\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffd\ufffd7\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307423,"ip":"34.76.60.10","ts":"2026-06-15 21:33:00.000000","proto":"tcp","src_port":44246,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.665674640437154, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022629c6a19110c80167b0f606003e7f4c9\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffdd$\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffdd$\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffdd$\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022b652a64bc43297685be1d4d572c9cb90daaaa69d\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffdd$\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffdd$\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffdd$\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffdd$\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307454,"ip":"34.76.60.10","ts":"2026-06-15 21:33:00.000000","proto":"tcp","src_port":44262,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.659457633828443, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022bf089461f6c035f73fd031a1be840742\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000r\\u0005$@\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000r\\u0005$@\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000r\\u0005$@\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00226660d2baeea4d0ed0a3cf751844bc040c9af2652\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000r\\u0005$@\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:r$@\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000r\\u0005$@\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:r$@\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307421,"ip":"34.76.60.10","ts":"2026-06-15 21:32:59.000000","proto":"tcp","src_port":44242,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.673605293289617, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022f112e49c4e72bc4fd77e169e2e9e1c10\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdf\ufffd\\u0019\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdf\ufffd\\u0019\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdf\ufffd\\u0019\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022a90ba1ec32ae83130626cb79f07f6ed9a0803f3e\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdf\ufffd\\u0019\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffdf\ufffd\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdf\ufffd\\u0019\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffdf\ufffd\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307419,"ip":"34.76.60.10","ts":"2026-06-15 21:32:58.000000","proto":"tcp","src_port":44222,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00220e0d0d07e7db573b1ef9e19aa009dc17\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\u001b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\u001b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\u001b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022ed0c1670ced967c1f8941b13d096c8aaeefbf3b9\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\u001b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffd\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\u001b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffd\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307420,"ip":"34.76.60.10","ts":"2026-06-15 21:32:58.000000","proto":"tcp","src_port":44232,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.673605293289617, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002273e6ffad1a06ab16d58e962a826d41e4\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdf\u003E\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdf\u003E\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdf\u003E\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022bf75cf3373f15032574be3cc05c758da27685983\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdf\u003E\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffdf\u003E\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdf\u003E\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffdf\u003E\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307417,"ip":"34.76.60.10","ts":"2026-06-15 21:32:57.000000","proto":"tcp","src_port":44204,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.6541789701364005, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00228b11c50567f9faaaf55bd691f5f563c5\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdyub\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdyub\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdyub\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002251b7668bb2ac02463d2dcae27cd3480433d5157f\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdyub\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffdyub\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdyub\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffdyub\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307418,"ip":"34.76.60.10","ts":"2026-06-15 21:32:57.000000","proto":"tcp","src_port":44218,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.6760093936149785, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002280674adbfe27345bdf28815c058de3b4\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\u003ES\\u0013\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\u003ES\\u0013\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\u003ES\\u0013\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022445424b1f042f730642346095b54c23811aa58b6\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\u003ES\\u0013\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd\u003ES\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\u003ES\\u0013\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd\u003ES\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true, \u0022behavior_alert_count\u0022: 2, \u0022behavior_priority\u0022: 72}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307413,"ip":"34.76.60.10","ts":"2026-06-15 21:32:56.000000","proto":"tcp","src_port":44190,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.6621606179920585, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002224e4a6b5a1d1348a696cd4cc87f95e3c\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffds\ufffd$\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffds\ufffd$\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffds\ufffd$\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022a67f20669fae1b99ee04d4667078c62560937638\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffds\ufffd$\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffds\ufffd$\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffds\ufffd$\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffds\ufffd$\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307414,"ip":"34.76.60.10","ts":"2026-06-15 21:32:56.000000","proto":"tcp","src_port":44200,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.666564163667069, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022ddcdedc511e45aaef5dfa175399e67bd\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\\r\\u000et\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\\r\\u000et\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\\r\\u000et\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022eb94eccae93690aa4fe9432ef329fdfa0294e5bc\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\\r\\u000et\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd\\rt\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\\r\\u000et\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd\\rt\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307411,"ip":"34.76.60.10","ts":"2026-06-15 21:32:55.000000","proto":"tcp","src_port":44176,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.661184482684871, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022bf111458c8a9d88b6ee50c92a13cc65c\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd4\ufffdl\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd4\ufffdl\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd4\ufffdl\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00222107b188d2ca93e7c3b0d3b9490abfcdae03f8c5\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd4\ufffdl\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd4\ufffdl\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd4\ufffdl\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd4\ufffdl\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307412,"ip":"34.76.60.10","ts":"2026-06-15 21:32:55.000000","proto":"tcp","src_port":44178,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022fce8f01a9c5fb234769da941880ae79f\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u00009\ufffd)}\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u00009\ufffd)}\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u00009\ufffd)}\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00220e8348b3001c8934b80574e22d2505c2bdd195f0\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u00009\ufffd)}\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:9\ufffd)}\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u00009\ufffd)}\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:9\ufffd)}\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307410,"ip":"34.76.60.10","ts":"2026-06-15 21:32:54.000000","proto":"tcp","src_port":44164,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.6760093936149785, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00229abff7809e388bbdd1ce0c9615e37d58\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd:\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd:\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd:\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00223e04a37cb259207c2712f9272de809713743c734\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd:\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffd\ufffd:\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd:\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffd\ufffd:\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307408,"ip":"34.76.60.10","ts":"2026-06-15 21:32:53.000000","proto":"tcp","src_port":44148,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.6760093936149785, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022ff73311c70b7f21c31c2d5fcb5329e58\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000T\ufffd^K\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000T\ufffd^K\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000T\ufffd^K\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022b169e12b4a901a2ef28d477dd790d3f7cab9da76\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000T\ufffd^K\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:T\ufffd^K\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000T\ufffd^K\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:T\ufffd^K\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307409,"ip":"34.76.60.10","ts":"2026-06-15 21:32:53.000000","proto":"tcp","src_port":44154,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002227c7237a14d37cbff7b7d69c54fe07f0\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd\\f\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd\\f\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd\\f\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00223ba5ad4fff81a6cf23ab2ac2b4b1f94b53808dce\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd\\f\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffd\ufffd\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\ufffd\\f\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffd\ufffd\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307406,"ip":"34.76.60.10","ts":"2026-06-15 21:32:52.000000","proto":"tcp","src_port":44116,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022a88b3c9b2ad734faed3a13eeedc8d21b\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd`\ufffdS\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd`\ufffdS\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd`\ufffdS\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022ca98e9c339299ed497c897226340c6921683765f\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd`\ufffdS\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd`\ufffdS\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd`\ufffdS\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd`\ufffdS\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307407,"ip":"34.76.60.10","ts":"2026-06-15 21:32:52.000000","proto":"tcp","src_port":44132,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.662109622988862, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022d2b5766b09dfa7ec011a4dc5ef0ebb72\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000k3;G\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000k3;G\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000k3;G\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00224c62e6221cb602935908c304045aba0beef10ca7\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000k3;G\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:k3;G\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000k3;G\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:k3;G\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307404,"ip":"34.76.60.10","ts":"2026-06-15 21:32:51.000000","proto":"tcp","src_port":55650,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.6760093936149785, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00220626330e60684e0f5e30a785205b7059\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\t}\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\t}\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\t}\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022959e3e9326da4439bd7ff162c6f18630ff8b0cc6\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\t}\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffd\\t}\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\t}\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffd\\t}\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307405,"ip":"34.76.60.10","ts":"2026-06-15 21:32:51.000000","proto":"tcp","src_port":55660,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002259c7580c013ab0fe9eca700fdd30cd61\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\u012a\ufffdB\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\u012a\ufffdB\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\u012a\ufffdB\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022c2c6182c7069acd2d0aae1b014e6b21d67fcbd17\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\u012a\ufffdB\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\u012a\ufffdB\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\u012a\ufffdB\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\u012a\ufffdB\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307403,"ip":"34.76.60.10","ts":"2026-06-15 21:32:50.000000","proto":"tcp","src_port":55638,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.673605293289617, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022028d74011763fce15ebe9476c0368ba6\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\u001df\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\u001df\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\u001df\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00225fad691baaa6592f561233ea12c5f05cc41f7a07\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\u001df\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffdf\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd\\u001df\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffdf\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307401,"ip":"34.76.60.10","ts":"2026-06-15 21:32:49.000000","proto":"tcp","src_port":55628,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.670883150065817, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022da489ead72c08d16b1c35f1096535478\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000*\ufffd\ufffdX\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000*\ufffd\ufffdX\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000*\ufffd\ufffdX\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022e1f664548270fab998b7a007e72d894e84943603\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000*\ufffd\ufffdX\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:*\ufffd\ufffdX\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000*\ufffd\ufffdX\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:*\ufffd\ufffdX\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307402,"ip":"34.76.60.10","ts":"2026-06-15 21:32:49.000000","proto":"tcp","src_port":55634,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.65574019623727, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022eadefbe6702e37a0fa4cefb095b530f4\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000^hf+\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000^hf+\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000^hf+\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022c9051a3cae858b5d05d4aca00dbc07f84c4024b7\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000^hf+\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:^hf+\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000^hf+\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:^hf+\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307399,"ip":"34.76.60.10","ts":"2026-06-15 21:32:48.000000","proto":"tcp","src_port":55614,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.6720440671887475, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002230536b9726bef7eeffe9ae94846a6ec4\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u00002\ufffd\\u001dN\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u00002\ufffd\\u001dN\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u00002\ufffd\\u001dN\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00228defc149fe59bc755768be4e952e54783fe214f7\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u00002\ufffd\\u001dN\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:2\ufffdN\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u00002\ufffd\\u001dN\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:2\ufffdN\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307400,"ip":"34.76.60.10","ts":"2026-06-15 21:32:48.000000","proto":"tcp","src_port":55624,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002241cb8c7e7b42cab87d8f0b3ff68939fb\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd7!\\f\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd7!\\f\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd7!\\f\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00223bea427c81162550b593edd8f522072fda24ec43\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd7!\\f\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd7!\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd7!\\f\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd7!\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307397,"ip":"34.76.60.10","ts":"2026-06-15 21:32:47.000000","proto":"tcp","src_port":55590,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022edc434b058b886db3c7f961f66365f18\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd!\u0027I\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd!\u0027I\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd!\u0027I\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022c0d1c7cd7f59f13255d854646391d11ca20741be\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd!\u0027I\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd!\u0027I\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd!\u0027I\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd!\u0027I\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307398,"ip":"34.76.60.10","ts":"2026-06-15 21:32:47.000000","proto":"tcp","src_port":55598,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.6760093936149785, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022a0d4c3b685b7a7a4f8b0635bbd6ce46c\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdD\ufffd\\u000b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdD\ufffd\\u000b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdD\ufffd\\u000b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00228a7dbcc5d876bccac92c3515c3e93498b9cc5cb5\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdD\ufffd\\u000b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffdD\ufffd\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdD\ufffd\\u000b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffdD\ufffd\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307395,"ip":"34.76.60.10","ts":"2026-06-15 21:32:46.000000","proto":"tcp","src_port":55574,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.655946984664884, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022f080700668f324fc6babf0c67d765ac6\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000J\ufffd3.\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000J\ufffd3.\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000J\ufffd3.\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022f9d3cc65acaef836c41e69bf0c5b4f1901a1712e\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000J\ufffd3.\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:J\ufffd3.\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000J\ufffd3.\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:J\ufffd3.\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307396,"ip":"34.76.60.10","ts":"2026-06-15 21:32:46.000000","proto":"tcp","src_port":55576,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.666564163667069, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00224a68763acd18915a46c6783999f187ef\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffdtj\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffdtj\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffdtj\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022e958321c5d6be5ac42f08dad7691b7d9bf92bfcf\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffdtj\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffdtj\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffdtj\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffdtj\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307394,"ip":"34.76.60.10","ts":"2026-06-15 21:32:45.000000","proto":"tcp","src_port":55564,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00220a7539333008c8eed8a1289c256e2505\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000S\ufffd]5\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000S\ufffd]5\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000S\ufffd]5\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022c4852f4dbf07b53897bbf0f0af124d6cfdadb126\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000S\ufffd]5\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:S\ufffd]5\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000S\ufffd]5\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:S\ufffd]5\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307392,"ip":"34.76.60.10","ts":"2026-06-15 21:32:44.000000","proto":"tcp","src_port":55540,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002236f928fe59da9b504d511f620cbfe45d\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\\u0019\ufffd\ufffd*\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\\u0019\ufffd\ufffd*\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\\u0019\ufffd\ufffd*\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022c8a0f9bd102d4b3dcd07b24b9e75d85127b0503a\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\\u0019\ufffd\ufffd*\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffd*\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\\u0019\ufffd\ufffd*\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffd*\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307393,"ip":"34.76.60.10","ts":"2026-06-15 21:32:44.000000","proto":"tcp","src_port":55552,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.6760093936149785, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002293c93fc7b1faf1abef1f8f4a56d559ec\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd(Q\\t\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd(Q\\t\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd(Q\\t\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022d6dcdfa4efbc35f0356048a868639223d64e12a1\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd(Q\\t\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd(Q\\t\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd(Q\\t\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd(Q\\t\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307390,"ip":"34.76.60.10","ts":"2026-06-15 21:32:43.000000","proto":"tcp","src_port":55526,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002280c12dd457697b5ac33a3dae35c152cb\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdQ!,\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdQ!,\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdQ!,\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002278b3db46c2a644e8e29bbbf4b5c187ff62c84880\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdQ!,\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffdQ!,\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdQ!,\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffdQ!,\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307391,"ip":"34.76.60.10","ts":"2026-06-15 21:32:43.000000","proto":"tcp","src_port":55532,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.666564163667069, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00223e5bf9c240a394d1c29bacbafd2d59d5\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdi\ufffd;\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdi\ufffd;\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdi\ufffd;\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022b21d411ce36c6febab64042639b977841ba8bdaf\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdi\ufffd;\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffdi\ufffd;\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdi\ufffd;\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffdi\ufffd;\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307388,"ip":"34.76.60.10","ts":"2026-06-15 21:32:42.000000","proto":"tcp","src_port":55494,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.6658270605800345, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002292a0e342874740f0558f4e2723597300\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000A\ufffd\ufffdr\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000A\ufffd\ufffdr\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000A\ufffd\ufffdr\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00226dff2d635491416fd24a1d1242aebb3a07872c85\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000A\ufffd\ufffdr\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:A\ufffd\ufffdr\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000A\ufffd\ufffdr\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:A\ufffd\ufffdr\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307389,"ip":"34.76.60.10","ts":"2026-06-15 21:32:42.000000","proto":"tcp","src_port":55510,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00222460850804418d62f576beafe14ec82c\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\\u0018][\\u0005\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\\u0018][\\u0005\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\\u0018][\\u0005\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00225cf9cac73c416d814fc00e93144d438503362e2f\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\\u0018][\\u0005\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:][\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\\u0018][\\u0005\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:][\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307386,"ip":"34.76.60.10","ts":"2026-06-15 21:32:41.000000","proto":"tcp","src_port":37946,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.670883150065816, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022efbaf51071a3d29f665a3177b69cd6c9\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd6\\u001b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd6\\u001b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd6\\u001b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002259749603a40d8c42e8b067c7caf5dc2bcc697ef6\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd6\\u001b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffd6\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\ufffd6\\u001b\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd\ufffd6\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307387,"ip":"34.76.60.10","ts":"2026-06-15 21:32:41.000000","proto":"tcp","src_port":37958,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002265ccd0353335a12b044961a1d42d9d5b\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000@\ufffd\ufffd!\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000@\ufffd\ufffd!\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000@\ufffd\ufffd!\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022932e9631b2557a475f8974287a00de35a95be6fe\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000@\ufffd\ufffd!\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:@\ufffd\ufffd!\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000@\ufffd\ufffd!\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:@\ufffd\ufffd!\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307385,"ip":"34.76.60.10","ts":"2026-06-15 21:32:40.000000","proto":"tcp","src_port":37938,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.6760093936149785, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002248956f9b6d44e457745a1984500f9dae\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\\u001a\\u0013GF\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\\u001a\\u0013GF\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\\u001a\\u0013GF\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022dbe73769a08065e9b12a70afb20ac25f75fce2be\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\\u001a\\u0013GF\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:GF\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\\u001a\\u0013GF\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:GF\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307383,"ip":"34.76.60.10","ts":"2026-06-15 21:32:39.000000","proto":"tcp","src_port":37918,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00220e9cd9f2f24cf4bcb6018ebf74732a7b\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000E*}\/\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000E*}\/\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000E*}\/\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022eefaee34e8e9e9a4ce1a8adbdc203ee314a3f37d\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000E*}\/\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:E*}\/\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000E*}\/\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:E*}\/\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307384,"ip":"34.76.60.10","ts":"2026-06-15 21:32:39.000000","proto":"tcp","src_port":37924,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.670883150065816, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022dea9d59bc8cf35edd416d2772db1d2a5\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000w\ufffd\ufffd6\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000w\ufffd\ufffd6\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000w\ufffd\ufffd6\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022c2f990db3eb52940c1b33a1a56b6222e558d3518\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000w\ufffd\ufffd6\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:w\ufffd\ufffd6\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000w\ufffd\ufffd6\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:w\ufffd\ufffd6\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307380,"ip":"34.76.60.10","ts":"2026-06-15 21:32:38.000000","proto":"tcp","src_port":37894,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00222e106efce657e6b79aeff7de082beda5\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\u061a\ufffdw\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\u061a\ufffdw\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\u061a\ufffdw\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022dd878f5cbf91d10e7fc68b8e5f47e6a40d4cc8b7\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\u061a\ufffdw\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\u061a\ufffdw\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\u061a\ufffdw\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\u061a\ufffdw\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307381,"ip":"34.76.60.10","ts":"2026-06-15 21:32:38.000000","proto":"tcp","src_port":37908,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.664513723314223, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00222aa0a5b23b633783c38bb7af8982fb24\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000hj|X\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000hj|X\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000hj|X\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002208653e6b26db678a06cca8cc132e61f283c338c9\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000hj|X\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:hj|X\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000hj|X\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:hj|X\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307378,"ip":"34.76.60.10","ts":"2026-06-15 21:32:37.000000","proto":"tcp","src_port":37874,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022b4f5d9d16aea17262e205e237bf9ad2a7cb165e0\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022266167a70b85aa80aec81b4824e03859\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\\u000fD\\rG\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\\u000fD\\rG\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\\u000fD\\rG\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00226e01429df594f7531ceae4091cb89aae7c2fa5ca\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\\u000fD\\rG\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:D\\rG\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\\u000fD\\rG\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:D\\rG\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307379,"ip":"34.76.60.10","ts":"2026-06-15 21:32:37.000000","proto":"tcp","src_port":37880,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.669639966863385, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 6, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c4ac3118d7473e99ee83d670158aed2aa3dc390c\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002212b2c6f94e6923b9423a62ffb4711f65\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd+T\\r\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd+T\\r\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd+T\\r\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022c76be549398d8afbf9926f1612128e6e20dd163e\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd+T\\r\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd+T\\r\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Rafale d\u0027authentification SSH \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd+T\\r\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd+T\\r\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_bruteforce_burst\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307374,"ip":"34.76.60.10","ts":"2026-06-15 21:32:36.000000","proto":"tcp","src_port":37860,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022b4f5d9d16aea17262e205e237bf9ad2a7cb165e0\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022dc43a00e8beac13ac6716a950e83d70d\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\\u001e}\ufffd\\u001c\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\\u001e}\ufffd\\u001c\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\\u001e}\ufffd\\u001c\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00224a8aee9c104317f66d0d05580273f853aee46fa5\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\\u001e}\ufffd\\u001c\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:}\ufffd\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\\u001e}\ufffd\\u001c\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:}\ufffd\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307377,"ip":"34.76.60.10","ts":"2026-06-15 21:32:36.000000","proto":"tcp","src_port":37862,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.669188662882251, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022b4f5d9d16aea17262e205e237bf9ad2a7cb165e0\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022971514ad680a79981f6e201d225ff29c\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdm\ufffd9\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdm\ufffd9\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdm\ufffd9\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022d8bd24aec8eb5d322825a0de64dcf7adcdd6aa3f\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdm\ufffd9\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffdm\ufffd9\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffdm\ufffd9\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffdm\ufffd9\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307371,"ip":"34.76.60.10","ts":"2026-06-15 21:32:35.000000","proto":"tcp","src_port":37850,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.68237882036657, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022b4f5d9d16aea17262e205e237bf9ad2a7cb165e0\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u00222abd8641b4356fb0962b60971e4958c2\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\u03af\\r\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\u03af\\r\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\u03af\\r\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00226ea2e0bf65a6d7b53da5a071f6f3c3ac3ab10f59\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\u03af\\r\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffd\u03af\\r\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\u03af\\r\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffd\u03af\\r\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314},{"id":9307307,"ip":"34.76.60.10","ts":"2026-06-15 21:32:34.000000","proto":"tcp","src_port":37834,"dst_port":27017,"service":"mongodb","classification":"mongodb_wire_protocol","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00223e000000000000000100000000000000dd070000000000001600000001000000000000001069736d6173746572000100000000016f6b0000000000f03f00\u0022, \u0022emulator_response_len\u0022: 62, \u0022bytes_in\u0022: 314, \u0022payload_entropy\u0022: 4.6658270605800345, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Google LLC\u0022, \u0022service\u0022: \u0022mongodb\u0022, \u0022app_proto\u0022: \u0022mongodb\u0022, \u0022asn\u0022: 396982, \u0022country\u0022: \u0022BE\u0022, \u0022dst_port\u0022: 27017, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 58.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 38, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022b4f5d9d16aea17262e205e237bf9ad2a7cb165e0\u0022, \u0022event_fingerprint\u0022: \u00223d0cef10d983b0efd34b4cdcc0b7c5f8287f4783\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 206, \u0022precision_signals\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022Mongo isMaster legacy\u0022, \u0022Mongo ismaster command\u0022, \u0022NFS RPC mount\u0022, \u0022STUN binding\u0022, \u0022Minecraft varint handshake\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022pat-0532\u0022, \u0022pat-0771\u0022, \u0022pat-0554\u0022, \u0022pat-0536\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022named_classification_skipped\u0022: false, \u0022classification_parent\u0022: \u0022mongodb_probe\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022BE\u0022, \u0022asn\u0022: 396982, \u0022org\u0022: \u0022Google LLC\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022af21c1e4c4ac814a25493c6847293f49\u0022, \u0022path_pattern_hash\u0022: \u00229060bd55aeb34075959b54fecab264ea\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022risk_score\u0022: 38}, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\\u0005rV\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\\u0005rV\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13.2\\u0000\\u0000\\u0003os\\u0000T\\u0000\\u0000\\u0000\\u0002type\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002name\\u0000\\u0006\\u0000\\u0000\\u0000Linux\\u0000\\u0002architecture\\u0000\\u0007\\u0000\\u0000\\u0000x86_64\\u0000\\u0002version\\u0000\\t\\u0000\\u0000\\u00006.12.68+\\u0000\\u0000\\u0002platform\\u0000\\u0017\\u0000\\u0000\\u0000CPython 3.13.3.final.0\u0022, \u0022payload_snippet\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\\u0005rV\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022database_scan\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022faad0e355e22daad86bdb8e7fcd9db4b83d48eb0\u0022, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\\u0005rV\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022evidence_snippet\u0022: \u0022:\ufffdrV\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab mongodb_wire_protocol \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 38\/100\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 58.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0, \u0022risk_score\u0022: 38}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 38, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022, \u0022dst_port\u0022: 27017, \u0022protocol_emulated\u0022: true, \u0022tags_summary\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022INT-upstream\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022ET-PROTO-MongoDB-Wire\u0022, \u0022pat-0363\u0022, \u0022pat-0364\u0022, \u0022Upstream\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: null, \u0022protocol_details\u0022: {\u0022mongodb_wire_fr\u0022: \u0022Protocole wire MongoDB (OP_QUERY\/OP_MSG)\u0022, \u0022payload_preview\u0022: \u0022:\\u0001\\u0000\\u0000\ufffd\\u0005rV\\u0000\\u0000\\u0000\\u0000\ufffd\\u0007\\u0000\\u0000\\u0000\\u0000\\u0000\\u0000admin.$cmd\\u0000\\u0000\\u0000\\u0000\\u0000\ufffd\ufffd\ufffd\ufffd\\u0013\\u0001\\u0000\\u0000\\u0010ismaster\\u0000\\u0001\\u0000\\u0000\\u0000\\bhelloOk\\u0000\\u0001\\u0003client\\u0000\ufffd\\u0000\\u0000\\u0000\\u0003driver\\u0000-\\u0000\\u0000\\u0000\\u0002name\\u0000\\n\\u0000\\u0000\\u0000PyMongo|c\\u0000\\u0002version\\u0000\\u0007\\u0000\\u0000\\u00004.13\u0022, \u0022port\u0022: 27017, \u0022service\u0022: \u0022mongodb\u0022, \u0022service_label_fr\u0022: \u0022MONGODB\u0022}, \u0022attack_vector\u0022: \u0022mongodb wire protocol \u00b7 via MONGODB:27017 \u00b7 (sonde \/ probe)\u0022, \u0022evidence_snippet\u0022: \u0022:\ufffdrV\ufffdadmin.$cmd\ufffd\ufffd\ufffd\ufffdismasterhelloOkclient\ufffddriver-name\\nPyMongo|cversion4.13\u0022, \u0022target_port_label\u0022: \u002227017 \u00b7 MONGODB\u0022, \u0022emulator_service\u0022: \u0022mongodb\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022mongodb\u0022, \u0022service_banner\u0022: \u0022honeypot-mongodb\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002227017\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022mongodb_emulated\u0022, \u0022mongodb_hello_probe\u0022, \u0022mongodb_wire_protocol\u0022, \u0022net_mongodb_wire_protocol\u0022, \u0022rdp_cookie_alt\u0022]","anomalies":"[]","severity":6,"bytes_in":314}],"total_events":287}