Profil de menace
Activité suspecte · risque 35/100
Période analysée : 2026-06-24 → 2026-07-24
Activité suspecte · risque 35/100
Campagne de scan — plusieurs IP du même /24 (85.217.149.0/24, ≥3 pairs)
Activité suspecte · risque 35/100
Synthèse décisionnelle honeypot — seuil de listing maintenu à 1 événement qualifié.
Type « postgres_probe » (signaux protocolaires) · confiance 49%
Confiance 59 % — Score WAF 8 · Bonus corrélation +10
ASN 209334 · 85.217.149.0/24 · RIPENCC — 8 pair(s) ASN/FAI listé(s) — activité locale élevée vs pairs · 498 événements sur la période pour cette IP.
Même FAI Modat B.V. — corrélation indicative.
Cette IP touche plusieurs services simulés (pas seulement le web).
Origine réseau déclarée
Opérateur et dernière activité ban
Score capteur — surveiller, investiguer ou bloquer.
Les dates De/À priment sur la période. Affinez protocole, port, service et classification.
498 événements filtrés — activité quotidienne
Top ports ciblés sur les dernières 24 heures
SSH 22, RDP 3389, HTTP alternatifs…
Web, SSH, SAP, scans…
Intensité par jour et heure (UTC capteur)
498 événement(s) — page 10/10
| Horodatage | Proto | Port | Service | Classification | Sévérité | Risque | Actions |
|---|---|---|---|---|---|---|---|
| TCP | 176 · HTTP | http | Scan de ports port scan syn · via HTTP:176 · (reconnaissance) | Élevée | Moyen · 60 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
176
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 60
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:176 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* A
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:176 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 448 · HTTP | http | Scan de ports port scan syn · via HTTP:448 · (reconnaissance) | Élevée | Moyen · 59 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
448
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +16
Risque capteur
Moyen
· 59
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:448 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* A
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:448 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 868 · HTTP | http | Scan de ports port scan syn · via HTTP:868 · (reconnaissance) | Élevée | Moyen · 56 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
868
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +16
Risque capteur
Moyen
· 56
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:868 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* A
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:868 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10593 · HTTP | http | Scan de ports port scan syn · via HTTP:10593 · (reconnaissance) | Élevée | Moyen · 60 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10593
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 60
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10593 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10593 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10087 · HTTP | http | Scan de ports port scan syn · via HTTP:10087 · (reconnaissance) | Élevée | Moyen · 58 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10087
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 58
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10087 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10087 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10222 · HTTP | http | Scan de ports port scan syn · via HTTP:10222 · (reconnaissance) | Élevée | Moyen · 60 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10222
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 60
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10222 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10222 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 4896 · HTTP | http | Scan de ports port scan syn · via HTTP:4896 · (reconnaissance) | Élevée | Moyen · 61 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
4896
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 61
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:4896 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:4896 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 9481 · HTTP | http | Scan de ports port scan syn · via HTTP:9481 · (reconnaissance) | Élevée | Moyen · 60 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
9481
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 60
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:9481 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:9481 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 4556 · HTTP | http | Scan de ports port scan syn · via HTTP:4556 · (reconnaissance) | Élevée | Moyen · 61 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
4556
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 61
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:4556 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:4556 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 9321 · HTTP | http | Scan de ports port scan syn · via HTTP:9321 · (reconnaissance) | Élevée | Moyen · 60 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
9321
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 60
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:9321 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:9321 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10862 · HTTP | http | Scan de ports port scan syn · via HTTP:10862 · (reconnaissance) | Élevée | Moyen · 58 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10862
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +16
Risque capteur
Moyen
· 58
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10862 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10862 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10103 · HTTP | http | Scan de ports port scan syn · via HTTP:10103 · (reconnaissance) | Élevée | Moyen · 61 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10103
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +16
Risque capteur
Moyen
· 61
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10103 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10103 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 9532 · HTTP | http | Scan de ports port scan syn · via HTTP:9532 · (reconnaissance) | Élevée | Moyen · 59 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
9532
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 59
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:9532 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:9532 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 9825 · HTTP | http | Scan de ports port scan syn · via HTTP:9825 · (reconnaissance) | Élevée | Moyen · 61 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
9825
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 61
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:9825 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:9825 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10545 · HTTP | http | Traversal LFI lfi path traversal · via HTTP:10545 · (tentative d'exploit) | Élevée | Moyen · 55 |
|
|
|
Étape
Tentative d'exploit
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
TA0001
TA0001
TA0002
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10545
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « lfi_path_traversal » (signaux protocolaires) · confiance 59%
Confiance classification
69%
Corrélation +10
Risque capteur
Moyen
· 55
Confiance : Confiance 59 % — 5 tag(s) WAF
Signaux
CRS-930100-sub
Technique MITRE
TA0001
Tactiques MITRE
TA0001
TA0002
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10545 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10545 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10102 · HTTP | http | Traversal LFI lfi path traversal · via HTTP:10102 · (tentative d'exploit) | Élevée | Moyen · 59 |
|
|
|
Étape
Tentative d'exploit
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
TA0001
TA0001
TA0002
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10102
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « lfi_path_traversal » (signaux protocolaires) · confiance 59%
Confiance classification
69%
Corrélation +10
Risque capteur
Moyen
· 59
Confiance : Confiance 59 % — 5 tag(s) WAF
Signaux
CRS-930100-sub
Technique MITRE
TA0001
Tactiques MITRE
TA0001
TA0002
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10102 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10102 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 9460 · HTTP | http | Scan de ports port scan syn · via HTTP:9460 · (reconnaissance) | Élevée | Moyen · 57 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
9460
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 57
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:9460 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:9460 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10651 · HTTP | http | Scan de ports port scan syn · via HTTP:10651 · (reconnaissance) | Élevée | Moyen · 60 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10651
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 60
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10651 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10651 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10413 · HTTP | http | Scan de ports port scan syn · via HTTP:10413 · (reconnaissance) | Élevée | Moyen · 61 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10413
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 61
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10413 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10413 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10576 · HTTP | http | Scan de ports port scan syn · via HTTP:10576 · (reconnaissance) | Élevée | Moyen · 58 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10576
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 58
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10576 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10576 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10358 · HTTP | http | Scan de ports port scan syn · via HTTP:10358 · (reconnaissance) | Élevée | Moyen · 58 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10358
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 58
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10358 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10358 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 30010 · HTTP | http | Scan de ports port scan syn · via HTTP:30010 · (reconnaissance) | Élevée | Moyen · 57 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
30010
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 57
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:30010 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:30010 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10382 · HTTP | http | Scan de ports port scan syn · via HTTP:10382 · (reconnaissance) | Élevée | Moyen · 61 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10382
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 61
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10382 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10382 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 30110 · HTTP | http | Scan de ports port scan syn · via HTTP:30110 · (reconnaissance) | Élevée | Moyen · 58 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
30110
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 58
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:30110 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:30110 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10665 · HTTP | http | Scan de ports port scan syn · via HTTP:10665 · (reconnaissance) | Élevée | Moyen · 57 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10665
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 57
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10665 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10665 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10474 · HTTP | http | Scan de ports port scan syn · via HTTP:10474 · (reconnaissance) | Élevée | Moyen · 61 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10474
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 61
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10474 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10474 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10316 · HTTP | http | Scan de ports port scan syn · via HTTP:10316 · (reconnaissance) | Élevée | Moyen · 61 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10316
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 61
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10316 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10316 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 30122 · HTTP | http | Scan de ports port scan syn · via HTTP:30122 · (reconnaissance) | Élevée | Moyen · 60 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
30122
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 60
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:30122 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:30122 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10508 · HTTP | http | Scan de ports port scan syn · via HTTP:10508 · (reconnaissance) | Élevée | Moyen · 62 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10508
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 62
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10508 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10508 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10347 · HTTP | http | Scan de ports port scan syn · via HTTP:10347 · (reconnaissance) | Élevée | Moyen · 61 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10347
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 61
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10347 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10347 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 4997 · HTTP | http | Scan de ports port scan syn · via HTTP:4997 · (reconnaissance) | Élevée | Moyen · 58 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
4997
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 58
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:4997 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:4997 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 30009 · HTTP | http | Scan de ports port scan syn · via HTTP:30009 · (reconnaissance) | Élevée | Moyen · 57 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
30009
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 57
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:30009 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:30009 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10365 · HTTP | http | Scan de ports port scan syn · via HTTP:10365 · (reconnaissance) | Élevée | Moyen · 58 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10365
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 58
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10365 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10365 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10536 · HTTP | http | Scan de ports port scan syn · via HTTP:10536 · (reconnaissance) | Élevée | Moyen · 61 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10536
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 61
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10536 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10536 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10466 · HTTP | http | Scan de ports port scan syn · via HTTP:10466 · (reconnaissance) | Élevée | Moyen · 59 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10466
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 59
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10466 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10466 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 30599 · HTTP | http | Scan de ports port scan syn · via HTTP:30599 · (reconnaissance) | Élevée | Moyen · 57 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
30599
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 57
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:30599 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:30599 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10630 · HTTP | http | Scan de ports port scan syn · via HTTP:10630 · (reconnaissance) | Élevée | Moyen · 61 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10630
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 61
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10630 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10630 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10502 · HTTP | http | Scan de ports port scan syn · via HTTP:10502 · (reconnaissance) | Élevée | Moyen · 61 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10502
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 61
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10502 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10502 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10488 · HTTP | http | Scan de ports port scan syn · via HTTP:10488 · (reconnaissance) | Élevée | Moyen · 59 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10488
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 59
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10488 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10488 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10311 · HTTP | http | Traversal LFI lfi path traversal · via HTTP:10311 · (tentative d'exploit) | Élevée | Moyen · 58 |
|
|
|
Étape
Tentative d'exploit
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
TA0001
TA0001
TA0002
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10311
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « lfi_path_traversal » (signaux protocolaires) · confiance 59%
Confiance classification
69%
Corrélation +10
Risque capteur
Moyen
· 58
Confiance : Confiance 59 % — 5 tag(s) WAF
Signaux
CRS-930100-sub
Technique MITRE
TA0001
Tactiques MITRE
TA0001
TA0002
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10311 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10311 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 30002 · HTTP | http | Scan de ports port scan syn · via HTTP:30002 · (reconnaissance) | Élevée | Moyen · 60 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
30002
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 60
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:30002 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:30002 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10438 · HTTP | http | Scan de ports port scan syn · via HTTP:10438 · (reconnaissance) | Élevée | Moyen · 60 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10438
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 60
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10438 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10438 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10553 · HTTP | http | Scan de ports port scan syn · via HTTP:10553 · (reconnaissance) | Élevée | Moyen · 58 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10553
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 58
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10553 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10553 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10467 · HTTP | http | Scan de ports port scan syn · via HTTP:10467 · (reconnaissance) | Élevée | Moyen · 59 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10467
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +20
Risque capteur
Moyen
· 59
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10467 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10467 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 10453 · HTTP | http | Traversal LFI lfi path traversal · via HTTP:10453 · (tentative d'exploit) | Élevée | Moyen · 56 |
|
|
|
Étape
Tentative d'exploit
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
TA0001
TA0001
TA0002
Protocole
GET / UA Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Émulateur
HTTP
WAF
30
Recommandation
Investiguer
Tags
Cible HTTP
GET
/
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
GET
Port
10453
Chemin / cible
/
Service
HTTP
Pourquoi cette classification : Type « lfi_path_traversal » (signaux protocolaires) · confiance 59%
Confiance classification
69%
Corrélation +10
Risque capteur
Moyen
· 56
Confiance : Confiance 59 % — 5 tag(s) WAF
Signaux
CRS-930100-sub
Technique MITRE
TA0001
Tactiques MITRE
TA0001
TA0002
Motifs de détection (base)
LFI Double-dot bypass
Ligne de requête
User-Agent
Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)
Règles WAF
lfi-14
rce-0
ssrf-3
nosqli-3
sap-sapcontrol-path
Payload (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10453 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */*
Requête brute (extrait)
GET / HTTP/1.1 Host: 62.3.50.33:10453 User-Agent: Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/) Accept: */* Accept-Encoding: gzip |
|||||||
| TCP | 17065 · TLS | tls | Sonde PostgreSQL postgres probe · via TLS:17065 · (sonde / probe) | Élevée | Faible · 35 |
|
|
|
Étape
Sonde / probe
Chaîne
Découverte
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
MITRE
TA0007
TA0007
TA0001
Protocole
JA3 35fa0a83e466acbe
Émulateur
TLS
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
17065
Chemin / cible
—
Service
TLS
Payload
� ��I�� =O�z.� B�e�ɔ b����A� Q��!�kJ^��o�"o�7�+_� +�Ň*,N�� &̨̩�/�0�+�,�� �� � � / 5� {
Pourquoi cette classification : Type « postgres_probe » (signaux protocolaires) · confiance 49%
Confiance classification
49%
Confiance modérée — signal unique
Risque capteur
Faible
· 35
Confiance : Confiance 49 % — Motif catalogue confirmé
Signaux
pat-0369
Technique MITRE
TA0007
Tactiques MITRE
TA0007
TA0001
Motifs de détection (base)
PostgreSQL startup
STUN binding
Minecraft varint handshake
SOCKS5 greeting
SIP TLS ClientHello
TFTP RRQ
User-Agent
—
Règles WAF
—
Payload (extrait)
� ��I�� =O�z.�B�e�ɔ b����A� Q��!�kJ^��o�"o�7�+_� +�Ň*,N�� &̨̩�/�0�+�,�� ��
� � / 5�
{
Requête brute (extrait)
� ��I�� =O�z.� B�e�ɔ b����A� Q��!�kJ^��o�"o�7�+_� +�Ň*,N�� &̨̩�/�0�+�,�� �� � � / 5� { � + 3 & | |||||||