{"ip":"65.111.13.4","exported_at":"2026-06-18T04:27:07+00:00","period_days":1,"metrics":{"events7d":2,"distinct_ports":1,"distinct_classifications":1,"max_severity":10,"last_sensor_id":"paris-1","max_waf_score":23,"max_risk_score":55,"attack_stage":"probe","attack_chain_stage":"discovery","threat_family":["unknown"],"recommended_action":"investigate","confidence":0.5,"risk_breakdown":{"waf":100,"classification":60,"behavior":0,"geo":0,"protocol":43,"novelty":25},"mitre_tactics":["TA0007","TA0001"],"mitre_technique":"TA0007","top_mitre_technique":"TA0007","top_mitre_count":2,"executive_one_liner_fr":"Activit\u00e9 suspecte \u2014 risque 55\/100 (Moyen) \u2014 MITRE TA0007 \u2014 confiance 50 % \u2014 via HTTP","campaign_hint_fr":null,"confidence_breakdown":{"waf":100,"classification":60,"behavior":0,"geo":0,"protocol":43,"novelty":25,"risk_score":55},"persona_hostname":"mail.sensor-1.internal","correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":50,"confidence_hint_fr":"Confiance mod\u00e9r\u00e9e \u2014 signal unique","sensor_role_label_fr":"Renseignement menaces","tags_summary_labels_fr":["Upstream","Waf Score"],"tags_summary":["INT-upstream","INT-waf-score"],"attack_vector":"probe api \u00b7 via HTTP:15672 \u00b7 (sonde \/ probe) \u00b7 \u2192 \/api\/queues","protocol_details":{"http_method":"GET","http_path":"\/api\/queues","request_line":"GET \/api\/queues HTTP\/1.1","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/132.0.0.0 Safari\/537.36 OPR\/117\u2026","port":15672,"service":"http","service_label_fr":"HTTP"},"protocol_summary_fr":"GET \/api\/queues \u00b7 UA Mozilla\/5.0 (Windows NT 10.0; Win64; x64) Apple\u2026 \u00b7 HTTP:15672","evidence_snippet":"GET \/api\/queues HTTP\/1.1\r\nHost: 62.3.50.33:15672\r\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTM","target_port_label":"15672 \u00b7 HTTP","emulator_service":"http","confidence_reason":"Confiance 50 % \u2014 4 tag(s) WAF","classification_reason":"Type \u00ab probe_api \u00bb (signaux protocolaires) \u00b7 confiance 50%","classification_reason_label_fr":"Type \u00ab probe_api \u00bb (signaux protocolaires) \u00b7 confiance 50%","confidence_factors_fr":"Confiance 50 % \u2014 Score WAF 100 \u00b7 4 tag(s) WAF","payload_preview":"GET \/api\/queues HTTP\/1.1\r\nHost: 62.3.50.33:15672\r\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTM"},"events":[],"total_events":0}