{"ip":"91.209.48.146","exported_at":"2026-08-05T14:14:30+00:00","period_days":30,"metrics":{"events7d":0,"distinct_ports":0,"distinct_classifications":0,"max_severity":null,"last_sensor_id":"paris-1","max_waf_score":null,"max_risk_score":42,"attack_stage":"recon","attack_chain_stage":"reconnaissance","threat_family":["scanner"],"recommended_action":"monitor","confidence":1,"risk_breakdown":{"waf":8,"classification":64,"behavior":0,"geo":0,"protocol":35,"novelty":15},"mitre_tactics":["TA0043"],"mitre_technique":"T1046","top_mitre_technique":"T1046","top_mitre_count":6,"executive_one_liner_fr":"Activit\u00e9 suspecte \u2014 risque 42\/100 (Moyen) \u2014 MITRE T1046 \u2014 confiance 100 % \u2014 via HTTP \u2014 campagne multi-ports","campaign_hint_fr":"Campagne multi-ports d\u00e9tect\u00e9e sur une fen\u00eatre courte","confidence_breakdown":{"waf":8,"classification":64,"behavior":0,"geo":0,"protocol":35,"novelty":15,"risk_score":42,"correlation_boost":10},"persona_hostname":"mail.sensor-1.internal","correlation_flags":["scan_rapide","campagne_ports"],"correlation_flags_labels_fr":["Scan rapide multi-ports","Campagne multi-ports"],"confidence_pct":100,"confidence_hint_fr":"Corr\u00e9lation +10","sensor_role_label_fr":"Renseignement menaces","tags_summary_labels_fr":["MITRE-T1046","SIGMA-net-port-scan","Beh Scan Burst","Beh Multi Port 60S"],"tags_summary":["MITRE-T1046","SIGMA-net-port-scan","INT-beh-scan-burst","INT-beh-multi-port-60s"],"attack_vector":"port scan syn \u00b7 via HTTP:8575 \u00b7 (reconnaissance) \u00b7 \u2192 \/health","protocol_details":{"http_method":"GET","http_path":"\/health","request_line":"GET \/health HTTP\/1.1","http_user_agent":"python-httpx\/0.28.1","port":8575,"service":"http","service_label_fr":"HTTP"},"protocol_summary_fr":"GET \/health \u00b7 UA python-httpx\/0.28.1 \u00b7 HTTP:8575","evidence_snippet":"GET \/health HTTP\/1.1\r\nHost: 62.3.50.33:8575\r\nUser-Agent: python-httpx\/0.28.1\r\nAccept: *\/*\r\nAccept-Encoding: gzip, deflate, br, z","target_port_label":"8575 \u00b7 HTTP","emulator_service":"http","confidence_reason":"Confiance 100 % \u2014 1 signal(aux) capteur","classification_reason":"Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%","classification_reason_label_fr":"Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%","confidence_factors_fr":"Confiance 100 % \u2014 Score WAF 8 \u00b7 Bonus corr\u00e9lation +10","payload_preview":"GET \/health HTTP\/1.1\r\nHost: 62.3.50.33:8575\r\nUser-Agent: python-httpx\/0.28.1\r\nAccept: *\/*\r\nAccept-Encoding: gzip, deflate, br, z"},"events":[{"id":13527314,"ip":"91.209.48.146","ts":"2026-07-24 09:09:30.000000","proto":"tcp","src_port":13791,"dst_port":18049,"service":"http","classification":"probe_health","waf_score":0,"waf_tags":"[]","http_method":"GET","http_target":"\/health","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022d274f19c345ec10bae4ba72e19bf3ff3de00f943\u0022, \u0022http_host_hash\u0022: \u0022f31a51b8e3c918b0410aacb2fda14fef9fb44053\u0022, \u0022http_target_hash\u0022: \u00220bb4da595b0ae9c7552fe95627a4f99f024f8c89\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 136, \u0022payload_entropy\u0022: 5.158733342175459, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 4637, \u0022country\u0022: \u0022TW\u0022, \u0022dst_port\u0022: 18049, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 1.5, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022add0f11d75064680da59bea3cf19c3616edbc8b4\u0022, \u0022event_fingerprint\u0022: \u00224f17d0331bb9fb23a08d6c409800561318084c47\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022INT-benign-health\u0022, \u0022INT-benign-path-cap\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab probe_health \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022TW\u0022, \u0022asn\u0022: 4637, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022ca9b2eafc1cd86346d14d7fab560d7bb\u0022, \u0022payload_hash\u0022: \u002277ebc8a09e3fbbf56d8176b095e69c50\u0022, \u0022path_pattern_hash\u0022: \u00220587c50e302cd55b995100e6e49c0789\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 18049, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 35}, \u0022payload_preview\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:18049\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, \u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:18049\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:18049\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:18049\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:18049\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab probe_health \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00229191d0ff73295d10f18b8a6a9d0b6f611745cd3e\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 18049, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:18049\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022attack_vector\u0022: \u0022probe health \u00b7 via HTTP:18049 \u00b7 (sonde \/ probe) \u00b7 \u2192 \/health\u0022, \u0022target_port_label\u0022: \u002218049 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab probe_health \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab probe_health \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 35\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 35, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 18049, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022INT-benign-health\u0022, \u0022INT-benign-path-cap\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022Benign Health\u0022, \u0022Chemin b\u00e9nin connu\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 18049, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022probe health \u00b7 via HTTP:18049 \u00b7 (sonde \/ probe) \u00b7 \u2192 \/health\u0022, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:18049\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022target_port_label\u0022: \u002218049 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002218049\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022http_probe_health\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:18049","http_user_agent":"python-httpx\/0.28.1","http_referer":null,"tags":"[\u0022http_probe_health\u0022]","anomalies":"[]","severity":4,"bytes_in":136},{"id":13527315,"ip":"91.209.48.146","ts":"2026-07-24 09:09:30.000000","proto":"tcp","src_port":38817,"dst_port":16100,"service":"http","classification":"probe_health","waf_score":0,"waf_tags":"[]","http_method":"GET","http_target":"\/health","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022d274f19c345ec10bae4ba72e19bf3ff3de00f943\u0022, \u0022http_host_hash\u0022: \u0022468f2d7ed5d35c5878089f046d359203d6f90dcc\u0022, \u0022http_target_hash\u0022: \u00220bb4da595b0ae9c7552fe95627a4f99f024f8c89\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 136, \u0022payload_entropy\u0022: 5.108330746791095, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 4637, \u0022country\u0022: \u0022TW\u0022, \u0022dst_port\u0022: 16100, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 32.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.1, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 35, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022f49bb940225e17d80d1cd2b4d61c6a67d6e030ae\u0022, \u0022event_fingerprint\u0022: \u0022cfb4ce955bf4f4fea5780afe7bb8d003d145435d\u0022, \u0022classification_confidence\u0022: 0.5, \u0022confidence\u0022: 0.5, \u0022precision_signals\u0022: [\u0022INT-benign-health\u0022, \u0022INT-benign-path-cap\u0022], \u0022classification_reason\u0022: \u0022Type \u00ab probe_health \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 50.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022TW\u0022, \u0022asn\u0022: 4637, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022ca9b2eafc1cd86346d14d7fab560d7bb\u0022, \u0022payload_hash\u0022: \u002244911a943e6ed1b21e06db9d0b63b147\u0022, \u0022path_pattern_hash\u0022: \u00220587c50e302cd55b995100e6e49c0789\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 16100, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 35}, \u0022payload_preview\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:16100\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, \u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:16100\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:16100\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:16100\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:16100\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab probe_health \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022mitre\u0022: \u0022TA0007\u0022, \u0022threat_family\u0022: [\u0022unknown\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002231b5622c31d5706b83ec5f016e2ac769f10f511a\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 16100, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:16100\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022attack_vector\u0022: \u0022probe health \u00b7 via HTTP:16100 \u00b7 (sonde \/ probe) \u00b7 \u2192 \/health\u0022, \u0022target_port_label\u0022: \u002216100 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab probe_health \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab probe_health \u00bb (signaux protocolaires) \u00b7 confiance 50%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u00b7 risque 35\/100\u0022, \u0022confidence_pct\u0022: 50, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 32.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 35}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022attack_stage_label\u0022: \u0022Sonde \/ probe\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022risk_score\u0022: 35, \u0022risk_label\u0022: \u0022Faible\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 16100, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022INT-benign-health\u0022, \u0022INT-benign-path-cap\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022Benign Health\u0022, \u0022Chemin b\u00e9nin connu\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022TA0007\u0022, \u0022mitre_technique\u0022: \u0022TA0007\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: null, \u0022correlation_flags_labels_fr\u0022: null, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Confiance mod\u00e9r\u00e9e \u2014 signal unique\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 16100, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022probe health \u00b7 via HTTP:16100 \u00b7 (sonde \/ probe) \u00b7 \u2192 \/health\u0022, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:16100\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022target_port_label\u0022: \u002216100 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 50 % \u2014 Motif catalogue confirm\u00e9\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 50 % \u2014 Score WAF 8\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022discovery\u0022, \u0022label_fr\u0022: \u0022D\u00e9couverte\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002216100\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022attack_chain_stage\u0022: \u0022discovery\u0022, \u0022matched_patterns\u0022: [], \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022http_probe_health\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:16100","http_user_agent":"python-httpx\/0.28.1","http_referer":null,"tags":"[\u0022http_probe_health\u0022]","anomalies":"[]","severity":4,"bytes_in":136},{"id":13527316,"ip":"91.209.48.146","ts":"2026-07-24 09:09:30.000000","proto":"tcp","src_port":4965,"dst_port":8076,"service":"http","classification":"port_scan_syn","waf_score":0,"waf_tags":"[]","http_method":"GET","http_target":"\/health","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022d274f19c345ec10bae4ba72e19bf3ff3de00f943\u0022, \u0022http_host_hash\u0022: \u002251351cf6517830208be4516a400b0f1c881839c2\u0022, \u0022http_target_hash\u0022: \u00220bb4da595b0ae9c7552fe95627a4f99f024f8c89\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 135, \u0022payload_entropy\u0022: 5.143022268337151, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 4637, \u0022country\u0022: \u0022TW\u0022, \u0022dst_port\u0022: 8076, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 64.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 2.9, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 42, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00222af0b88e26b4cee23f582f518af7bf5635dfd14d\u0022, \u0022event_fingerprint\u0022: \u002205e4d830d8cc6a6bd0618dfb597735f68c95c699\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 231, \u0022precision_signals\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022matched_patterns\u0022: [\u0022pat-0596\u0022, \u0022pat-0439\u0022], \u0022matched_pattern_names\u0022: [\u0022Sigma httpx tool\u0022, \u0022UA httpx\u0022], \u0022pattern_ids\u0022: [\u0022pat-0596\u0022, \u0022pat-0439\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 42, \u0022correlation_boost\u0022: 4}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022TW\u0022, \u0022asn\u0022: 4637, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022ca9b2eafc1cd86346d14d7fab560d7bb\u0022, \u0022payload_hash\u0022: \u0022e445678669d00623de8bf8b928514e5e\u0022, \u0022path_pattern_hash\u0022: \u00220587c50e302cd55b995100e6e49c0789\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8076, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 42}, \u0022payload_preview\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8076\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8076\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8076\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8076\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8076\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022recon\u0022, \u0022mitre_tactics\u0022: [\u0022TA0043\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00222358b9d48a41313f21dfcdfc7ca870e235faf88b\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 8076, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8076\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022attack_vector\u0022: \u0022port scan syn \u00b7 via HTTP:8076 \u00b7 (reconnaissance) \u00b7 \u2192 \/health\u0022, \u0022target_port_label\u0022: \u00228076 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 1 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 42\/100 (Moyen) \u2014 MITRE T1046 \u2014 confiance 100 % \u2014 via HTTP\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 42, \u0022correlation_boost\u0022: 4}, \u0022attack_stage\u0022: \u0022recon\u0022, \u0022attack_stage_label\u0022: \u0022Reconnaissance\u0022, \u0022attack_chain_stage\u0022: \u0022reconnaissance\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Reconnaissance\u0022, \u0022risk_score\u0022: 42, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 8076, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022Beh Multi Port 60S\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: [\u0022scan_rapide\u0022], \u0022correlation_flags_labels_fr\u0022: [\u0022Scan rapide multi-ports\u0022], \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Corr\u00e9lation +4\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 8076, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022port scan syn \u00b7 via HTTP:8076 \u00b7 (reconnaissance) \u00b7 \u2192 \/health\u0022, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8076\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022target_port_label\u0022: \u00228076 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 1 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8 \u00b7 Bonus corr\u00e9lation +4\u0022, \u0022campaign_hint_fr\u0022: null, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022reconnaissance\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228076\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022rapid_port_scan\u0022: true, \u0022rapid_scan_distinct_ports\u0022: 3, \u0022scan_velocity_ports_per_s\u0022: 30.0, \u0022behavior_alerts\u0022: [\u0022rapid_port_scan\u0022], \u0022correlation_confidence_boost\u0022: 4, \u0022attack_chain_stage\u0022: \u0022reconnaissance\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022http_probe_health\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8076","http_user_agent":"python-httpx\/0.28.1","http_referer":null,"tags":"[\u0022http_probe_health\u0022]","anomalies":"[]","severity":4,"bytes_in":135},{"id":13527317,"ip":"91.209.48.146","ts":"2026-07-24 09:09:30.000000","proto":"tcp","src_port":62853,"dst_port":22000,"service":"http","classification":"port_scan_syn","waf_score":0,"waf_tags":"[]","http_method":"GET","http_target":"\/health","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022d274f19c345ec10bae4ba72e19bf3ff3de00f943\u0022, \u0022http_host_hash\u0022: \u0022a153e5f72c04e8a17b3da8f4103e06403af160cb\u0022, \u0022http_target_hash\u0022: \u00220bb4da595b0ae9c7552fe95627a4f99f024f8c89\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 136, \u0022payload_entropy\u0022: 5.102780103392835, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 4637, \u0022country\u0022: \u0022TW\u0022, \u0022dst_port\u0022: 22000, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 64.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.7, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 42, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u002245c4e6aeb4e48a3a638c29f08c251a435233914c\u0022, \u0022event_fingerprint\u0022: \u0022ab2d2401db5190bde1a915d6cd32b44bcafa1478\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 231, \u0022precision_signals\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022matched_patterns\u0022: [\u0022pat-0596\u0022, \u0022pat-0439\u0022], \u0022matched_pattern_names\u0022: [\u0022Sigma httpx tool\u0022, \u0022UA httpx\u0022], \u0022pattern_ids\u0022: [\u0022pat-0596\u0022, \u0022pat-0439\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 42, \u0022correlation_boost\u0022: 10}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022TW\u0022, \u0022asn\u0022: 4637, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022ca9b2eafc1cd86346d14d7fab560d7bb\u0022, \u0022payload_hash\u0022: \u0022cf6846f19453cfbf1fc9e90da95fa499\u0022, \u0022path_pattern_hash\u0022: \u00220587c50e302cd55b995100e6e49c0789\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 22000, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 42}, \u0022payload_preview\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:22000\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, \u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:22000\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:22000\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:22000\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:22000\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022recon\u0022, \u0022mitre_tactics\u0022: [\u0022TA0043\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022e8970b8d8424de1e04b729be9980b15783ac464d\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 22000, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:22000\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022attack_vector\u0022: \u0022port scan syn \u00b7 via HTTP:22000 \u00b7 (reconnaissance) \u00b7 \u2192 \/health\u0022, \u0022target_port_label\u0022: \u002222000 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 1 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 42\/100 (Moyen) \u2014 MITRE T1046 \u2014 confiance 100 % \u2014 via HTTP \u2014 campagne multi-ports\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 42, \u0022correlation_boost\u0022: 10}, \u0022attack_stage\u0022: \u0022recon\u0022, \u0022attack_stage_label\u0022: \u0022Reconnaissance\u0022, \u0022attack_chain_stage\u0022: \u0022reconnaissance\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Reconnaissance\u0022, \u0022risk_score\u0022: 42, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 22000, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022Beh Multi Port 60S\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: [\u0022scan_rapide\u0022, \u0022campagne_ports\u0022], \u0022correlation_flags_labels_fr\u0022: [\u0022Scan rapide multi-ports\u0022, \u0022Campagne multi-ports\u0022], \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Corr\u00e9lation +10\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 22000, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022port scan syn \u00b7 via HTTP:22000 \u00b7 (reconnaissance) \u00b7 \u2192 \/health\u0022, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:22000\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022target_port_label\u0022: \u002222000 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 1 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8 \u00b7 Bonus corr\u00e9lation +10\u0022, \u0022campaign_hint_fr\u0022: \u0022Campagne multi-ports d\u00e9tect\u00e9e sur une fen\u00eatre courte\u0022, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022reconnaissance\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002222000\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022port_scan_campaign\u0022: true, \u0022port_scan_distinct_ports\u0022: 4, \u0022port_scan_ports_sample\u0022: [8076, 16100, 18049, 22000], \u0022rapid_port_scan\u0022: true, \u0022rapid_scan_distinct_ports\u0022: 4, \u0022scan_velocity_ports_per_s\u0022: 40.0, \u0022behavior_alerts\u0022: [\u0022port_scan_campaign\u0022, \u0022rapid_port_scan\u0022], \u0022correlation_confidence_boost\u0022: 10, \u0022attack_chain_stage\u0022: \u0022reconnaissance\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022http_probe_health\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:22000","http_user_agent":"python-httpx\/0.28.1","http_referer":null,"tags":"[\u0022http_probe_health\u0022]","anomalies":"[]","severity":4,"bytes_in":136},{"id":13527318,"ip":"91.209.48.146","ts":"2026-07-24 09:09:30.000000","proto":"tcp","src_port":4409,"dst_port":8024,"service":"http","classification":"port_scan_syn","waf_score":0,"waf_tags":"[]","http_method":"GET","http_target":"\/health","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022d274f19c345ec10bae4ba72e19bf3ff3de00f943\u0022, \u0022http_host_hash\u0022: \u002216abed6f1c6c78464861e2240eaf23de55acf579\u0022, \u0022http_target_hash\u0022: \u00220bb4da595b0ae9c7552fe95627a4f99f024f8c89\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 135, \u0022payload_entropy\u0022: 5.137430509061866, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 4637, \u0022country\u0022: \u0022TW\u0022, \u0022dst_port\u0022: 8024, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 64.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 4.5, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 42, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00229b4613509438d4d09ed1b9f873f8d107ff14a0e3\u0022, \u0022event_fingerprint\u0022: \u00229a0c2553babdb5fc9bb32d44f41a095f9ee8f4db\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 293, \u0022precision_signals\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-scan-burst\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-scan-burst\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022matched_patterns\u0022: [\u0022pat-0596\u0022, \u0022pat-0439\u0022], \u0022matched_pattern_names\u0022: [\u0022Sigma httpx tool\u0022, \u0022UA httpx\u0022], \u0022pattern_ids\u0022: [\u0022pat-0596\u0022, \u0022pat-0439\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 42, \u0022correlation_boost\u0022: 10}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022TW\u0022, \u0022asn\u0022: 4637, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022ca9b2eafc1cd86346d14d7fab560d7bb\u0022, \u0022payload_hash\u0022: \u002234184660cbd96662042990c6ccf7f14d\u0022, \u0022path_pattern_hash\u0022: \u00220587c50e302cd55b995100e6e49c0789\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8024, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 42}, \u0022payload_preview\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8024\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8024\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8024\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8024\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8024\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022recon\u0022, \u0022mitre_tactics\u0022: [\u0022TA0043\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022050986478db677e0dc72e96bd874ffd9ea2c6692\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 8024, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8024\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022attack_vector\u0022: \u0022port scan syn \u00b7 via HTTP:8024 \u00b7 (reconnaissance) \u00b7 \u2192 \/health\u0022, \u0022target_port_label\u0022: \u00228024 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 1 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 42\/100 (Moyen) \u2014 MITRE T1046 \u2014 confiance 100 % \u2014 via HTTP \u2014 campagne multi-ports\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 42, \u0022correlation_boost\u0022: 10}, \u0022attack_stage\u0022: \u0022recon\u0022, \u0022attack_stage_label\u0022: \u0022Reconnaissance\u0022, \u0022attack_chain_stage\u0022: \u0022reconnaissance\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Reconnaissance\u0022, \u0022risk_score\u0022: 42, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 8024, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-scan-burst\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022Beh Scan Burst\u0022, \u0022Beh Multi Port 60S\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: [\u0022scan_rapide\u0022, \u0022campagne_ports\u0022], \u0022correlation_flags_labels_fr\u0022: [\u0022Scan rapide multi-ports\u0022, \u0022Campagne multi-ports\u0022], \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Corr\u00e9lation +10\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 8024, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022port scan syn \u00b7 via HTTP:8024 \u00b7 (reconnaissance) \u00b7 \u2192 \/health\u0022, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8024\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022target_port_label\u0022: \u00228024 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 1 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8 \u00b7 Bonus corr\u00e9lation +10\u0022, \u0022campaign_hint_fr\u0022: \u0022Campagne multi-ports d\u00e9tect\u00e9e sur une fen\u00eatre courte\u0022, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022reconnaissance\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228024\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022port_scan_campaign\u0022: true, \u0022port_scan_distinct_ports\u0022: 5, \u0022port_scan_ports_sample\u0022: [8024, 8076, 16100, 18049, 22000], \u0022rapid_port_scan\u0022: true, \u0022rapid_scan_distinct_ports\u0022: 5, \u0022scan_velocity_ports_per_s\u0022: 50.0, \u0022behavior_alerts\u0022: [\u0022port_scan_campaign\u0022, \u0022rapid_port_scan\u0022], \u0022correlation_confidence_boost\u0022: 10, \u0022attack_chain_stage\u0022: \u0022reconnaissance\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022http_probe_health\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8024","http_user_agent":"python-httpx\/0.28.1","http_referer":null,"tags":"[\u0022http_probe_health\u0022]","anomalies":"[]","severity":4,"bytes_in":135},{"id":13527319,"ip":"91.209.48.146","ts":"2026-07-24 09:09:30.000000","proto":"tcp","src_port":28421,"dst_port":3160,"service":"http","classification":"port_scan_syn","waf_score":0,"waf_tags":"[]","http_method":"GET","http_target":"\/health","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022d274f19c345ec10bae4ba72e19bf3ff3de00f943\u0022, \u0022http_host_hash\u0022: \u00222ed477da899e82f66276bb76f09136174338ef7d\u0022, \u0022http_target_hash\u0022: \u00220bb4da595b0ae9c7552fe95627a4f99f024f8c89\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 135, \u0022payload_entropy\u0022: 5.109761342443276, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 4637, \u0022country\u0022: \u0022TW\u0022, \u0022dst_port\u0022: 3160, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 64.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 5.0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 42, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022aa0707311d85e4b0836a2d2d24ad318180831cad\u0022, \u0022event_fingerprint\u0022: \u00221f81a0d3d9430ef493e00cdf8b9bc5d90f639eca\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 293, \u0022precision_signals\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-scan-burst\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-scan-burst\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022matched_patterns\u0022: [\u0022pat-0596\u0022, \u0022pat-0439\u0022], \u0022matched_pattern_names\u0022: [\u0022Sigma httpx tool\u0022, \u0022UA httpx\u0022], \u0022pattern_ids\u0022: [\u0022pat-0596\u0022, \u0022pat-0439\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 42, \u0022correlation_boost\u0022: 10}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022TW\u0022, \u0022asn\u0022: 4637, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022ca9b2eafc1cd86346d14d7fab560d7bb\u0022, \u0022payload_hash\u0022: \u00221886dd113c39708c05cd2d0fdcf46707\u0022, \u0022path_pattern_hash\u0022: \u00220587c50e302cd55b995100e6e49c0789\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 3160, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 42}, \u0022payload_preview\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:3160\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:3160\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:3160\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:3160\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:3160\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022recon\u0022, \u0022mitre_tactics\u0022: [\u0022TA0043\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u00228e126940819328191d85035d0357c1f3cd9d19e1\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 3160, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:3160\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022attack_vector\u0022: \u0022port scan syn \u00b7 via HTTP:3160 \u00b7 (reconnaissance) \u00b7 \u2192 \/health\u0022, \u0022target_port_label\u0022: \u00223160 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 1 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 42\/100 (Moyen) \u2014 MITRE T1046 \u2014 confiance 100 % \u2014 via HTTP \u2014 campagne multi-ports\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 42, \u0022correlation_boost\u0022: 10}, \u0022attack_stage\u0022: \u0022recon\u0022, \u0022attack_stage_label\u0022: \u0022Reconnaissance\u0022, \u0022attack_chain_stage\u0022: \u0022reconnaissance\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Reconnaissance\u0022, \u0022risk_score\u0022: 42, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 3160, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-scan-burst\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022Beh Scan Burst\u0022, \u0022Beh Multi Port 60S\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: [\u0022scan_rapide\u0022, \u0022campagne_ports\u0022], \u0022correlation_flags_labels_fr\u0022: [\u0022Scan rapide multi-ports\u0022, \u0022Campagne multi-ports\u0022], \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Corr\u00e9lation +10\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 3160, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022port scan syn \u00b7 via HTTP:3160 \u00b7 (reconnaissance) \u00b7 \u2192 \/health\u0022, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:3160\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022target_port_label\u0022: \u00223160 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 1 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8 \u00b7 Bonus corr\u00e9lation +10\u0022, \u0022campaign_hint_fr\u0022: \u0022Campagne multi-ports d\u00e9tect\u00e9e sur une fen\u00eatre courte\u0022, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022reconnaissance\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00223160\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022port_scan_campaign\u0022: true, \u0022port_scan_distinct_ports\u0022: 6, \u0022port_scan_ports_sample\u0022: [3160, 8024, 8076, 16100, 18049, 22000], \u0022rapid_port_scan\u0022: true, \u0022rapid_scan_distinct_ports\u0022: 6, \u0022scan_velocity_ports_per_s\u0022: 60.0, \u0022behavior_alerts\u0022: [\u0022port_scan_campaign\u0022, \u0022rapid_port_scan\u0022], \u0022correlation_confidence_boost\u0022: 10, \u0022attack_chain_stage\u0022: \u0022reconnaissance\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022http_probe_health\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3160","http_user_agent":"python-httpx\/0.28.1","http_referer":null,"tags":"[\u0022http_probe_health\u0022]","anomalies":"[]","severity":4,"bytes_in":135},{"id":13527320,"ip":"91.209.48.146","ts":"2026-07-24 09:09:30.000000","proto":"tcp","src_port":35907,"dst_port":12281,"service":"http","classification":"port_scan_syn","waf_score":0,"waf_tags":"[]","http_method":"GET","http_target":"\/health","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022d274f19c345ec10bae4ba72e19bf3ff3de00f943\u0022, \u0022http_host_hash\u0022: \u0022b8b067432788d318070430ef43923cc20e0f68c8\u0022, \u0022http_target_hash\u0022: \u00220bb4da595b0ae9c7552fe95627a4f99f024f8c89\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 136, \u0022payload_entropy\u0022: 5.108330746791097, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 4637, \u0022country\u0022: \u0022TW\u0022, \u0022dst_port\u0022: 12281, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 64.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 1.1, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 42, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00228ffa2c20bd5bc621f79475782e225ad475c4f58b\u0022, \u0022event_fingerprint\u0022: \u002208dd5c78c23ca6f44b6f76073a646260509d77eb\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 293, \u0022precision_signals\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-scan-burst\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-scan-burst\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022matched_patterns\u0022: [\u0022pat-0596\u0022, \u0022pat-0439\u0022], \u0022matched_pattern_names\u0022: [\u0022Sigma httpx tool\u0022, \u0022UA httpx\u0022], \u0022pattern_ids\u0022: [\u0022pat-0596\u0022, \u0022pat-0439\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 42, \u0022correlation_boost\u0022: 10}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022TW\u0022, \u0022asn\u0022: 4637, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022ca9b2eafc1cd86346d14d7fab560d7bb\u0022, \u0022payload_hash\u0022: \u00224c1550fc3c957baefaaf989046795b97\u0022, \u0022path_pattern_hash\u0022: \u00220587c50e302cd55b995100e6e49c0789\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 12281, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 42}, \u0022payload_preview\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:12281\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, \u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:12281\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:12281\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:12281\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:12281\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022recon\u0022, \u0022mitre_tactics\u0022: [\u0022TA0043\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022bf4e3cf84ea8734fcffd6379c827933e41a20648\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 12281, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:12281\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022attack_vector\u0022: \u0022port scan syn \u00b7 via HTTP:12281 \u00b7 (reconnaissance) \u00b7 \u2192 \/health\u0022, \u0022target_port_label\u0022: \u002212281 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 1 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 42\/100 (Moyen) \u2014 MITRE T1046 \u2014 confiance 100 % \u2014 via HTTP \u2014 campagne multi-ports\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 42, \u0022correlation_boost\u0022: 10}, \u0022attack_stage\u0022: \u0022recon\u0022, \u0022attack_stage_label\u0022: \u0022Reconnaissance\u0022, \u0022attack_chain_stage\u0022: \u0022reconnaissance\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Reconnaissance\u0022, \u0022risk_score\u0022: 42, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 12281, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-scan-burst\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022Beh Scan Burst\u0022, \u0022Beh Multi Port 60S\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: [\u0022scan_rapide\u0022, \u0022campagne_ports\u0022], \u0022correlation_flags_labels_fr\u0022: [\u0022Scan rapide multi-ports\u0022, \u0022Campagne multi-ports\u0022], \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Corr\u00e9lation +10\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 12281, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022port scan syn \u00b7 via HTTP:12281 \u00b7 (reconnaissance) \u00b7 \u2192 \/health\u0022, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:12281\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br,\u0022, \u0022target_port_label\u0022: \u002212281 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 1 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8 \u00b7 Bonus corr\u00e9lation +10\u0022, \u0022campaign_hint_fr\u0022: \u0022Campagne multi-ports d\u00e9tect\u00e9e sur une fen\u00eatre courte\u0022, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022reconnaissance\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u002212281\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022port_scan_campaign\u0022: true, \u0022port_scan_distinct_ports\u0022: 7, \u0022port_scan_ports_sample\u0022: [3160, 8024, 8076, 12281, 16100, 18049, 22000], \u0022rapid_port_scan\u0022: true, \u0022rapid_scan_distinct_ports\u0022: 7, \u0022scan_velocity_ports_per_s\u0022: 70.0, \u0022behavior_alerts\u0022: [\u0022port_scan_campaign\u0022, \u0022rapid_port_scan\u0022], \u0022correlation_confidence_boost\u0022: 10, \u0022attack_chain_stage\u0022: \u0022reconnaissance\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022http_probe_health\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:12281","http_user_agent":"python-httpx\/0.28.1","http_referer":null,"tags":"[\u0022http_probe_health\u0022]","anomalies":"[]","severity":4,"bytes_in":136},{"id":13527321,"ip":"91.209.48.146","ts":"2026-07-24 09:09:30.000000","proto":"tcp","src_port":21607,"dst_port":8575,"service":"http","classification":"port_scan_syn","waf_score":0,"waf_tags":"[]","http_method":"GET","http_target":"\/health","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022d274f19c345ec10bae4ba72e19bf3ff3de00f943\u0022, \u0022http_host_hash\u0022: \u0022d5667348204d04a272d429aef58e3caa2384f632\u0022, \u0022http_target_hash\u0022: \u00220bb4da595b0ae9c7552fe95627a4f99f024f8c89\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 135, \u0022payload_entropy\u0022: 5.143022268337151, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 4637, \u0022country\u0022: \u0022TW\u0022, \u0022dst_port\u0022: 8575, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 64.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 35.0, \u0022risk_novelty\u0022: 15.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 3.4, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0}, \u0022risk_score\u0022: 42, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00227b834ed28a21b0b4fe41c06017975e618f8c26ed\u0022, \u0022event_fingerprint\u0022: \u0022ee8bc5095f731a5d95a42013028afe2431a79146\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 293, \u0022precision_signals\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-scan-burst\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022kb_rule_ids\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-scan-burst\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022matched_patterns\u0022: [\u0022pat-0596\u0022, \u0022pat-0439\u0022], \u0022matched_pattern_names\u0022: [\u0022Sigma httpx tool\u0022, \u0022UA httpx\u0022], \u0022pattern_ids\u0022: [\u0022pat-0596\u0022, \u0022pat-0439\u0022], \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 42, \u0022correlation_boost\u0022: 10}, \u0022named_classification_skipped\u0022: false, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022TW\u0022, \u0022asn\u0022: 4637, \u0022org\u0022: \u0022Telstra Global\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022http_ua_hash\u0022: \u0022ca9b2eafc1cd86346d14d7fab560d7bb\u0022, \u0022payload_hash\u0022: \u0022d8f9a91e762f8cded6552309ed6492c8\u0022, \u0022path_pattern_hash\u0022: \u00220587c50e302cd55b995100e6e49c0789\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 8575, \u0022service\u0022: \u0022http\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022risk_score\u0022: 42}, \u0022payload_preview\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8575\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8575\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8575\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022evidence\u0022: {\u0022method\u0022: \u0022GET\u0022, \u0022path\u0022: \u0022\/health\u0022, \u0022user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022request_sample\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8575\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, zstd\\r\\n\\r\\n\u0022, \u0022payload_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8575\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022recon\u0022, \u0022mitre_tactics\u0022: [\u0022TA0043\u0022], \u0022mitre_techniques\u0022: [\u0022T1046\u0022], \u0022mitre\u0022: \u0022T1046\u0022, \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u002250cb41001018e306efdb63398bec0ce59fdaeb28\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 8575, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8575\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022attack_vector\u0022: \u0022port scan syn \u00b7 via HTTP:8575 \u00b7 (reconnaissance) \u00b7 \u2192 \/health\u0022, \u0022target_port_label\u0022: \u00228575 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 1 signal(aux) capteur\u0022, \u0022site_display\u0022: {\u0022classification\u0022: null, \u0022classification_reason\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022classification_reason_label_fr\u0022: \u0022Type \u00ab port_scan_syn \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022executive_one_liner_fr\u0022: \u0022Activit\u00e9 suspecte \u2014 risque 42\/100 (Moyen) \u2014 MITRE T1046 \u2014 confiance 100 % \u2014 via HTTP \u2014 campagne multi-ports\u0022, \u0022confidence_pct\u0022: 100, \u0022confidence_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 64.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 35.0, \u0022novelty\u0022: 15.0, \u0022risk_score\u0022: 42, \u0022correlation_boost\u0022: 10}, \u0022attack_stage\u0022: \u0022recon\u0022, \u0022attack_stage_label\u0022: \u0022Reconnaissance\u0022, \u0022attack_chain_stage\u0022: \u0022reconnaissance\u0022, \u0022attack_chain_stage_label_fr\u0022: \u0022Reconnaissance\u0022, \u0022risk_score\u0022: 42, \u0022risk_label\u0022: \u0022Moyen\u0022, \u0022service_name\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022, \u0022dst_port\u0022: 8575, \u0022protocol_emulated\u0022: null, \u0022tags_summary\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022INT-beh-scan-burst\u0022, \u0022INT-beh-multi-port-60s\u0022], \u0022tags_summary_labels_fr\u0022: [\u0022MITRE-T1046\u0022, \u0022SIGMA-net-port-scan\u0022, \u0022Beh Scan Burst\u0022, \u0022Beh Multi Port 60S\u0022], \u0022recommended_action\u0022: \u0022monitor\u0022, \u0022recommended_action_label\u0022: \u0022Surveiller\u0022, \u0022mitre\u0022: \u0022T1046\u0022, \u0022mitre_technique\u0022: \u0022T1046\u0022, \u0022persona_hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022persona_service_banner\u0022: \u0022honeypot-http\u0022, \u0022correlation_flags\u0022: [\u0022scan_rapide\u0022, \u0022campagne_ports\u0022], \u0022correlation_flags_labels_fr\u0022: [\u0022Scan rapide multi-ports\u0022, \u0022Campagne multi-ports\u0022], \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022sensor_role_label_fr\u0022: \u0022Renseignement menaces\u0022, \u0022confidence_hint_fr\u0022: \u0022Corr\u00e9lation +10\u0022, \u0022protocol_details\u0022: {\u0022http_method\u0022: \u0022GET\u0022, \u0022http_path\u0022: \u0022\/health\u0022, \u0022request_line\u0022: \u0022GET \/health HTTP\/1.1\u0022, \u0022http_user_agent\u0022: \u0022python-httpx\/0.28.1\u0022, \u0022port\u0022: 8575, \u0022service\u0022: \u0022http\u0022, \u0022service_label_fr\u0022: \u0022HTTP\u0022}, \u0022attack_vector\u0022: \u0022port scan syn \u00b7 via HTTP:8575 \u00b7 (reconnaissance) \u00b7 \u2192 \/health\u0022, \u0022evidence_snippet\u0022: \u0022GET \/health HTTP\/1.1\\r\\nHost: 62.3.50.33:8575\\r\\nUser-Agent: python-httpx\/0.28.1\\r\\nAccept: *\/*\\r\\nAccept-Encoding: gzip, deflate, br, z\u0022, \u0022target_port_label\u0022: \u00228575 \u00b7 HTTP\u0022, \u0022emulator_service\u0022: \u0022http\u0022, \u0022confidence_reason\u0022: \u0022Confiance 100 % \u2014 1 signal(aux) capteur\u0022, \u0022confidence_factors_fr\u0022: \u0022Confiance 100 % \u2014 Score WAF 8 \u00b7 Bonus corr\u00e9lation +10\u0022, \u0022campaign_hint_fr\u0022: \u0022Campagne multi-ports d\u00e9tect\u00e9e sur une fen\u00eatre courte\u0022, \u0022attack_phases_timeline_fr\u0022: [{\u0022key\u0022: \u0022recon\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022probe\u0022, \u0022label_fr\u0022: \u0022Sonde \/ probe\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022exploit_attempt\u0022, \u0022label_fr\u0022: \u0022Tentative d\u0027exploit\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022post_exploit\u0022, \u0022label_fr\u0022: \u0022Post-exploitation\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022c2\u0022, \u0022label_fr\u0022: \u0022Commande \u0026 contr\u00f4le\u0022, \u0022active\u0022: false, \u0022kind\u0022: \u0022stage\u0022}, {\u0022key\u0022: \u0022reconnaissance\u0022, \u0022label_fr\u0022: \u0022Reconnaissance\u0022, \u0022active\u0022: true, \u0022kind\u0022: \u0022chain\u0022, \u0022hint_fr\u0022: null}]}, \u0022honeypot_persona\u0022: {\u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022mail_host\u0022: \u0022mail.sensor-1.internal\u0022, \u0022ldap_dc\u0022: \u0022dc.sensor-1.internal\u0022, \u0022k8s_cluster\u0022: \u0022hp-sensor-1\u0022, \u0022domain\u0022: \u0022sensor-1.internal\u0022, \u0022service_role\u0022: \u0022http\u0022, \u0022service_banner\u0022: \u0022honeypot-http\u0022, \u0022service_os\u0022: \u0022linux\u0022, \u0022dst_port\u0022: \u00228575\u0022}, \u0022hostname\u0022: \u0022mail.sensor-1.internal\u0022, \u0022sensor_id\u0022: \u0022sensor-1\u0022, \u0022port_scan_campaign\u0022: true, \u0022port_scan_distinct_ports\u0022: 8, \u0022port_scan_ports_sample\u0022: [3160, 8024, 8076, 8575, 12281, 16100, 18049, 22000], \u0022rapid_port_scan\u0022: true, \u0022rapid_scan_distinct_ports\u0022: 8, \u0022scan_velocity_ports_per_s\u0022: 80.0, \u0022behavior_alerts\u0022: [\u0022port_scan_campaign\u0022, \u0022rapid_port_scan\u0022], \u0022correlation_confidence_boost\u0022: 10, \u0022attack_chain_stage\u0022: \u0022reconnaissance\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022http_probe_health\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8575","http_user_agent":"python-httpx\/0.28.1","http_referer":null,"tags":"[\u0022http_probe_health\u0022]","anomalies":"[]","severity":4,"bytes_in":135}],"total_events":8}