Skip to content

scythe-8af8785e SESSION-858ec5d25a7b6232

1 PCAPs β€’ 79 sessions β€’ 45 hosts β€’ 29 πŸŒ geolocated

β–Ά πŸ“„ cap_05182026_430pmCST.pcapng

354.9 KB β€’ 79 sessions β€’ UDP:30 TCP:45 ICMP:3 OTHER:1

Paths: 25
Physical: 25
Synthetic: 0
Cables: 8
IX: 2
Conflicts: 0
CSI: 0
Cascades: 0
πŸ‘» Phantoms: 0
Kill Chain: 0
AS15169 β†’ AS249403 hops Β· 0%
AS15169 β†’ AS3356 β†’ AS24940
8076 km
βœ“ PHYSICALπŸ”— CABLE AS15169 β†’ AS80753 hops Β· 0%
AS15169 β†’ AS3356 β†’ AS8075
πŸ”— AAG (Asia-America Gateway), JUPITER
1722 km
βœ“ PHYSICALπŸ”— CABLE AS15169 β†’ AS541133 hops Β· 0%
AS15169 β†’ AS3356 β†’ AS54113
πŸ”— AAG (Asia-America Gateway), JUPITER
560 km
βœ“ PHYSICALπŸ”— CABLE AS15169 β†’ AS80753 hops Β· 0%
AS15169 β†’ AS3356 β†’ AS8075
πŸ”— AAG (Asia-America Gateway), JUPITER
928 km
⚑ IX AS15169 β†’ AS146183 hops Β· 0%
AS15169 β†’ AS3356 β†’ AS14618
⚑ Equinix Chicago
1683 km
AS15169 β†’ AS80753 hops Β· 0%
AS15169 β†’ AS3356 β†’ AS8075
559 km
βœ“ PHYSICALπŸ”— CABLE AS15169 β†’ AS3969822 hops Β· 0%
AS15169 β†’ AS396982
πŸ”— AAG (Asia-America Gateway), JUPITER
320 km
βœ“ PHYSICALπŸ”— CABLE AS24940 β†’ AS80753 hops Β· 0%
AS24940 β†’ AS3356 β†’ AS8075
πŸ”— Grace Hopper
7006 km
AS24940 β†’ AS541133 hops Β· 0%
AS24940 β†’ AS3356 β†’ AS54113
8451 km
AS24940 β†’ AS80753 hops Β· 0%
AS24940 β†’ AS3356 β†’ AS8075
8844 km
βœ“ PHYSICALπŸ”— CABLE AS24940 β†’ AS146183 hops Β· 0%
AS24940 β†’ AS3356 β†’ AS14618
πŸ”— Grace Hopper
6536 km
AS24940 β†’ AS80753 hops Β· 0%
AS24940 β†’ AS3356 β†’ AS8075
7516 km
AS24940 β†’ AS3969823 hops Β· 0%
AS24940 β†’ AS3356 β†’ AS396982
7780 km
βœ“ PHYSICALπŸ”— CABLE AS8075 β†’ AS541133 hops Β· 0%
AS8075 β†’ AS3356 β†’ AS54113
πŸ”— AAG (Asia-America Gateway), JUPITER
1735 km
βœ“ PHYSICALπŸ”— CABLE⚑ IX AS8075 β†’ AS146183 hops Β· 0%
AS8075 β†’ AS3356 β†’ AS14618
πŸ”— Grace Hopper, Firmina, Dunant, FLAG Atlantic-1, MAREA
⚑ Equinix Ashburn
779 km
βœ“ PHYSICALπŸ”— CABLE⚑ IX AS8075 β†’ AS3969823 hops Β· 0%
AS8075 β†’ AS3356 β†’ AS396982
πŸ”— AAG (Asia-America Gateway), JUPITER
⚑ Equinix Chicago
1444 km
βœ“ PHYSICALπŸ”— CABLE AS54113 β†’ AS80753 hops Β· 0%
AS54113 β†’ AS3356 β†’ AS8075
πŸ”— AAG (Asia-America Gateway), JUPITER
406 km
⚑ IX AS54113 β†’ AS146183 hops Β· 0%
AS54113 β†’ AS3356 β†’ AS14618
⚑ Equinix Chicago
1936 km
AS54113 β†’ AS80753 hops Β· 0%
AS54113 β†’ AS3356 β†’ AS8075
1021 km
βœ“ PHYSICALπŸ”— CABLE AS54113 β†’ AS3969823 hops Β· 0%
AS54113 β†’ AS3356 β†’ AS396982
πŸ”— AAG (Asia-America Gateway), JUPITER
731 km
[6:02:09 PM] βœ“ 25 paths Β· 0 synthetic
KindIDLabelsPosition
asnasn:54113asn=54,113, org=Fastly, Inc.
asnasn:24940asn=24,940, org=Hetzner Online GmbH
asnasn:397273asn=397,273, org=Render
asnasn:20940asn=20,940, org=Akamai International B.V.
asnasn:16509asn=16,509, org=Amazon.com, Inc.
asnasn:8075asn=8,075, org=Microsoft Corporation
asnasn:36236asn=36,236, org=NetActuate, Inc
asnasn:396982asn=396,982, org=Google LLC
asnasn:15169asn=15,169, org=Google LLC
asnasn:6167asn=6,167, org=Verizon Business
asnasn:14618asn=14,618, org=Amazon.com, Inc.
behavior_groupBSG-DATA_EXFIL-e7f288856e4cbehavior=DATA_EXFIL, confidence=0.5, detection_rationale=total_bytes=32594, dst_ip=, member_count=1, src_ip=209.177.156.94, summary=Exfil suspect: 209.177.156.94 β†’ 1 destinations, 32,594B total, max 32,594B/session, total_bytes=32,594, total_packets=115, unique_hosts=1, unique_ports=0
behavior_groupBSG-BEACON-3fa1dca5627cbehavior=BEACON, confidence=0.9, detection_rationale=timing_cv=0.00 (≀0.5); byte_cv=0.00 (≀0.6), dst_ip=151.101.113.140, dst_port=443, interval_cv=0, mean_interval=0, member_count=3, src_ip=192.168.1.185, summary=Beacon: 192.168.1.185 β†’ 151.101.113.140:443, 3 sessions, interval CV=0.00, mean 121B, total_bytes=363, total_packets=6, unique_hosts=0, unique_ports=0
behavior_groupBSG-HORIZ_SCAN-cd2c52661c4bbehavior=HORIZ_SCAN, confidence=0.8, detection_rationale=unique_hosts=19; short_sessions=84%, dst_ip=, dst_port=443, member_count=31, src_ip=192.168.1.185, summary=Horizontal scan: 192.168.1.185 β†’ 19 hosts on port 443, 31 sessions, total_bytes=255,098, total_packets=442, unique_hosts=19, unique_ports=0
behavior_groupBSG-DATA_EXFIL-78b438a917b5behavior=DATA_EXFIL, confidence=0.95, detection_rationale=total_bytes=207718; large_volume (β‰₯100KB); high_rate (67388 B/s); repeated (5 sessions), dst_ip=, member_count=5, src_ip=192.168.1.185, summary=Exfil suspect: 192.168.1.185 β†’ 4 destinations, 207,718B total, max 141,514B/session, total_bytes=207,718, total_packets=246, unique_hosts=4, unique_ports=0
behavior_groupBSG-BEACON-4bc57cbec7cdbehavior=BEACON, confidence=0.9, detection_rationale=timing_cv=0.00 (≀0.5); byte_cv=0.41 (≀0.6), dst_ip=192.168.1.1, dst_port=46,407, interval_cv=0, mean_interval=0, member_count=3, src_ip=192.168.1.185, summary=Beacon: 192.168.1.185 β†’ 192.168.1.1:46407, 3 sessions, interval CV=0.00, mean 2713B, total_bytes=8,138, total_packets=32, unique_hosts=0, unique_ports=0
dns_namedns:wpad.mynetworksettings.comanswer_count=0, qname=wpad.mynetworksettings.com
dns_namedns:bat.bing.comanswer_count=4, qname=bat.bing.com
dns_namedns:signaler-pa.clients6.google.comanswer_count=1, qname=signaler-pa.clients6.google.com
dns_namedns:browser.events.data.microsoft.comanswer_count=3, qname=browser.events.data.microsoft.com
dns_namedns:ctldl.windowsupdate.comanswer_count=8, qname=ctldl.windowsupdate.com
dns_namedns:remotedesktop-pa.googleapis.comanswer_count=9, qname=remotedesktop-pa.googleapis.com
dns_namedns:chatgpt.comanswer_count=6, qname=chatgpt.com
dns_namedns:copilot.microsoft.comanswer_count=4, qname=copilot.microsoft.com
flowflow:f25397a8d5d5bytes=11,087, dst_ip=104.18.32.47, dst_port=443, pkts=18, proto=tcp, src_ip=192.168.1.185
flowflow:478de54cd94abytes=498, dst_ip=97.178.32.239, dst_port=31,036, pkts=3, proto=udp, src_ip=192.168.1.185
flowflow:abe950115ba3bytes=121, dst_ip=13.107.226.57, dst_port=443, pkts=2, proto=tcp, src_ip=192.168.1.185
flowflow:9d482c927ad5bytes=1,924, dst_ip=192.200.0.112, dst_port=443, pkts=5, proto=tcp, src_ip=192.168.1.185
flowflow:027ad06c15d5bytes=321, dst_ip=192.168.1.185, dst_port=55,880, pkts=5, proto=tcp, src_ip=104.18.36.216
flowflow:e36e1209129dbytes=228, dst_ip=192.168.1.185, dst_port=51,049, pkts=3, proto=tcp, src_ip=216.24.57.251
flowflow:c65476284ea0bytes=321, dst_ip=192.168.1.185, dst_port=61,509, pkts=5, proto=tcp, src_ip=162.159.128.61
flowflow:189be888c3afbytes=13,297, dst_ip=104.18.23.222, dst_port=443, pkts=21, proto=tcp, src_ip=192.168.1.185
flowflow:bab9257727f6bytes=137, dst_ip=23.219.160.5, dst_port=443, pkts=2, proto=udp, src_ip=192.168.1.185
flowflow:b41e05b0f148bytes=156, dst_ip=209.177.158.246, dst_port=3,478, pkts=2, proto=udp, src_ip=192.168.1.185
flowflow:f6fc82e11042bytes=218, dst_ip=192.168.1.1, dst_port=5,351, pkts=4, proto=udp, src_ip=192.168.1.185
flowflow:660ca437efa1bytes=1,712, dst_ip=192.168.1.1, dst_port=53, pkts=14, proto=udp, src_ip=192.168.1.185
flowflow:779733f74cebbytes=441, dst_ip=104.208.203.89, dst_port=443, pkts=4, proto=tcp, src_ip=192.168.1.185
flowflow:4eed5ff51111bytes=1,782, dst_ip=192.168.1.1, dst_port=46,407, pkts=10, proto=tcp, src_ip=192.168.1.185
flowflow:4ac806f4d834bytes=422, dst_ip=20.62.59.32, dst_port=443, pkts=6, proto=tcp, src_ip=192.168.1.185
flowflow:ef26bc2c964dbytes=321, dst_ip=192.168.1.185, dst_port=62,104, pkts=5, proto=tcp, src_ip=172.64.151.22
flowflow:21a678dc75debytes=1,951, dst_ip=199.165.136.100, dst_port=443, pkts=6, proto=tcp, src_ip=192.168.1.185
flowflow:a25fcb74f721bytes=228, dst_ip=192.168.1.185, dst_port=58,631, pkts=3, proto=tcp, src_ip=216.24.57.7
flowflow:7395be855a32bytes=3,492, dst_ip=192.168.1.185, dst_port=0, pkts=18, proto=icmp, src_ip=97.178.32.239
flowflow:0523b90826b8bytes=193, dst_ip=192.168.1.185, dst_port=51,645, pkts=2, proto=tcp, src_ip=192.200.0.112
flowflow:cb933110cf94bytes=5,086, dst_ip=199.165.136.100, dst_port=443, pkts=25, proto=tcp, src_ip=192.168.1.185
flowflow:df281449ac19bytes=1,164, dst_ip=192.168.1.185, dst_port=0, pkts=6, proto=icmp, src_ip=97.178.32.239
flowflow:46c89f86a16abytes=245, dst_ip=23.219.160.5, dst_port=443, pkts=3, proto=udp, src_ip=192.168.1.185
flowflow:00f4e10d6ac7bytes=2,508, dst_ip=192.168.1.185, dst_port=43,844, pkts=15, proto=tcp, src_ip=209.177.156.94
flowflow:9cc54a60d88abytes=4,440, dst_ip=192.168.1.185, dst_port=54,986, pkts=5, proto=tcp, src_ip=167.235.217.196
flowflow:300bb0be41cfbytes=121, dst_ip=151.101.113.140, dst_port=443, pkts=2, proto=tcp, src_ip=192.168.1.185
flowflow:03d3562fa35fbytes=498, dst_ip=97.178.32.239, dst_port=52,243, pkts=3, proto=udp, src_ip=192.168.1.185
flowflow:ab2fda60ec38bytes=121, dst_ip=150.171.28.10, dst_port=443, pkts=2, proto=tcp, src_ip=192.168.1.185
flowflow:7fc08133133dbytes=498, dst_ip=172.19.0.1, dst_port=44,244, pkts=3, proto=udp, src_ip=192.168.1.185
flowflow:26faad66f81ebytes=498, dst_ip=172.18.0.1, dst_port=44,244, pkts=3, proto=udp, src_ip=192.168.1.185
flowflow:4f5810e72704bytes=156, dst_ip=192.73.244.245, dst_port=3,478, pkts=2, proto=udp, src_ip=192.168.1.185
flowflow:007f4ea11c64bytes=121, dst_ip=135.234.174.40, dst_port=443, pkts=2, proto=tcp, src_ip=192.168.1.185
flowflow:82ce7409c0cabytes=893, dst_ip=151.101.114.172, dst_port=80, pkts=7, proto=tcp, src_ip=192.168.1.185
flowflow:df1c396b8733bytes=306, dst_ip=192.168.1.185, dst_port=51,966, pkts=5, proto=tcp, src_ip=23.213.232.172
flowflow:f5abaef54664bytes=4,269, dst_ip=192.168.1.1, dst_port=46,407, pkts=12, proto=tcp, src_ip=192.168.1.185
flowflow:481a8cb33c5bbytes=230, dst_ip=192.168.1.1, dst_port=5,351, pkts=4, proto=udp, src_ip=192.168.1.185
flowflow:a3f08c1df1f5bytes=30,133, dst_ip=192.73.248.83, dst_port=443, pkts=96, proto=tcp, src_ip=192.168.1.185
flowflow:c0b4f157e073bytes=121, dst_ip=34.111.31.13, dst_port=443, pkts=2, proto=tcp, src_ip=192.168.1.185
flowflow:dc8e0c394478bytes=410, dst_ip=192.168.1.1, dst_port=53, pkts=4, proto=udp, src_ip=192.168.1.185
flowflow:1fbee9feb06dbytes=321, dst_ip=192.168.1.185, dst_port=51,146, pkts=5, proto=tcp, src_ip=104.18.1.62
flowflow:d479ce3b7365bytes=141, dst_ip=192.168.1.185, dst_port=54,629, pkts=2, proto=tcp, src_ip=52.110.6.13
flowflow:bf7a9427297dbytes=1,621, dst_ip=192.168.1.1, dst_port=0, pkts=5, proto=icmp, src_ip=192.168.1.185
flowflow:05b4e5b174c0bytes=3,585, dst_ip=192.168.1.185, dst_port=54,986, pkts=4, proto=tcp, src_ip=167.235.217.196
flowflow:341692033057bytes=498, dst_ip=97.178.32.239, dst_port=41,641, pkts=3, proto=udp, src_ip=192.168.1.185
flowflow:5b983251f483bytes=1,002, dst_ip=192.168.1.185, dst_port=52,133, pkts=14, proto=tcp, src_ip=104.18.22.222
flowflow:0c699e4ab5c4bytes=822, dst_ip=192.168.1.1, dst_port=53, pkts=6, proto=udp, src_ip=192.168.1.185
flowflow:d658b18ff560bytes=120, dst_ip=224.0.0.22, dst_port=0, pkts=2, proto=other, src_ip=192.168.1.165
flowflow:bf8f4a131249bytes=498, dst_ip=172.17.0.1, dst_port=44,244, pkts=3, proto=udp, src_ip=192.168.1.185
flowflow:a912cd07306bbytes=498, dst_ip=172.29.16.1, dst_port=41,641, pkts=3, proto=udp, src_ip=192.168.1.185
flowflow:c378386f9a22bytes=3,906, dst_ip=150.171.28.10, dst_port=443, pkts=11, proto=tcp, src_ip=192.168.1.185
flowflow:65175f124256bytes=642, dst_ip=199.165.136.100, dst_port=443, pkts=4, proto=tcp, src_ip=192.168.1.185
flowflow:7986b2093729bytes=11,687, dst_ip=104.18.32.47, dst_port=443, pkts=21, proto=tcp, src_ip=192.168.1.185
flowflow:51a92af49050bytes=121, dst_ip=76.76.21.22, dst_port=443, pkts=2, proto=tcp, src_ip=192.168.1.185
flowflow:d84a13678d67bytes=8,541, dst_ip=142.250.113.95, dst_port=443, pkts=20, proto=udp, src_ip=192.168.1.185
flowflow:dd3dd13e1b60bytes=156, dst_ip=209.177.158.246, dst_port=3,478, pkts=2, proto=udp, src_ip=192.168.1.185
flowflow:495f7c8d94fdbytes=32,594, dst_ip=192.168.1.185, dst_port=43,844, pkts=115, proto=tcp, src_ip=209.177.156.94
flowflow:e34282443dabbytes=1,532, dst_ip=142.250.115.95, dst_port=443, pkts=11, proto=udp, src_ip=192.168.1.185
flowflow:1cae684ccaf1bytes=121, dst_ip=35.190.80.1, dst_port=443, pkts=2, proto=tcp, src_ip=192.168.1.185
flowflow:a42e7b1c53d5bytes=156, dst_ip=209.177.156.94, dst_port=3,478, pkts=2, proto=udp, src_ip=192.168.1.185
flowflow:7be9da9aa76dbytes=141,514, dst_ip=52.182.143.215, dst_port=443, pkts=90, proto=tcp, src_ip=192.168.1.185
flowflow:60dd2a974649bytes=230, dst_ip=192.168.1.1, dst_port=5,351, pkts=4, proto=udp, src_ip=192.168.1.185
flowflow:65c7de267840bytes=218, dst_ip=192.168.1.1, dst_port=5,351, pkts=4, proto=udp, src_ip=192.168.1.185
flowflow:0380e0cd29dcbytes=220, dst_ip=192.168.1.185, dst_port=52,640, pkts=3, proto=tcp, src_ip=104.18.39.21
flowflow:f79c1639a1f7bytes=498, dst_ip=97.178.32.239, dst_port=11,130, pkts=3, proto=udp, src_ip=192.168.1.185
flowflow:f3b81336df74bytes=121, dst_ip=151.101.112.217, dst_port=443, pkts=2, proto=tcp, src_ip=192.168.1.185
flowflow:f19ee6508782bytes=220, dst_ip=192.168.1.185, dst_port=58,457, pkts=3, proto=tcp, src_ip=104.18.39.21
flowflow:46f60ddc23a2bytes=2,087, dst_ip=192.168.1.1, dst_port=46,407, pkts=10, proto=tcp, src_ip=192.168.1.185
flowflow:62d01d1bf747bytes=156, dst_ip=192.73.243.135, dst_port=3,478, pkts=2, proto=udp, src_ip=192.168.1.185
flowflow:fdf049da8b14bytes=156, dst_ip=209.177.156.94, dst_port=3,478, pkts=2, proto=udp, src_ip=192.168.1.185
flowflow:6fe67514daf4bytes=2,238, dst_ip=192.73.248.83, dst_port=443, pkts=13, proto=tcp, src_ip=192.168.1.185
flowflow:3d20532e84edbytes=9,890, dst_ip=23.219.160.5, dst_port=443, pkts=40, proto=udp, src_ip=192.168.1.185
flowflow:919c57e90236bytes=8,434, dst_ip=142.250.115.95, dst_port=443, pkts=21, proto=udp, src_ip=192.168.1.185
flowflow:c44b4fd56f98bytes=298, dst_ip=192.168.1.185, dst_port=60,920, pkts=4, proto=udp, src_ip=216.239.32.223
flowflow:137f07aaadb4bytes=498, dst_ip=97.178.32.239, dst_port=41,641, pkts=3, proto=udp, src_ip=192.168.1.185
flowflow:d83699920b5bbytes=121, dst_ip=151.101.113.140, dst_port=443, pkts=2, proto=tcp, src_ip=192.168.1.185
flowflow:682d5368c69ebytes=498, dst_ip=97.178.32.239, dst_port=1,050, pkts=3, proto=udp, src_ip=192.168.1.185
flowflow:eb3b47352f67bytes=121, dst_ip=151.101.113.140, dst_port=443, pkts=2, proto=tcp, src_ip=192.168.1.185
flowflow:9aa8161296f7bytes=660, dst_ip=199.165.136.100, dst_port=443, pkts=3, proto=tcp, src_ip=192.168.1.185
flowflow:5a246bdf60e4bytes=121, dst_ip=135.234.174.40, dst_port=443, pkts=2, proto=tcp, src_ip=192.168.1.185
geo_pointgeo_34.05440_-118.24400city=Los Angeles, country=US[34.0544, -118.2440, 0.0000] πŸŒ
geo_pointgeo_29.42270_-98.49270city=San Antonio, country=US[29.4227, -98.4927, 0.0000] πŸŒ
geo_pointgeo_29.75390_-95.35900city=Houston, country=US[29.7539, -95.3590, 0.0000] πŸŒ
geo_pointgeo_34.02330_-117.85120city=Walnut, country=US[34.0233, -117.8512, 0.0000] πŸŒ
geo_pointgeo_38.70950_-78.15390city=Washington, country=US[38.7095, -78.1539, 0.0000] πŸŒ
geo_pointgeo_41.88350_-87.63050city=Chicago, country=US[41.8835, -87.6305, 0.0000] πŸŒ
geo_pointgeo_37.75100_-97.82200city=, country=US[37.7510, -97.8220, 0.0000] πŸŒ
geo_pointgeo_43.63190_-79.37160city=, country=CA[43.6319, -79.3716, 0.0000] πŸŒ
geo_pointgeo_36.66940_-78.38770city=Boydton, country=US[36.6694, -78.3877, 0.0000] πŸŒ
geo_pointgeo_29.82840_-95.46960city=Houston, country=US[29.8284, -95.4696, 0.0000] πŸŒ
geo_pointgeo_39.10270_-94.57780city=Kansas City, country=US[39.1027, -94.5778, 0.0000] πŸŒ
geo_pointgeo_32.77970_-96.80220city=Dallas, country=US[32.7797, -96.8022, 0.0000] πŸŒ
geo_pointgeo_50.47770_12.36490city=Falkenstein, country=DE[50.4777, 12.3649, 0.0000] πŸŒ
geo_pointgeo_41.60150_-93.61270city=Des Moines, country=US[41.6015, -93.6127, 0.0000] πŸŒ
geo_pointgeo_25.77010_-80.19280city=Miami, country=US[25.7701, -80.1928, 0.0000] πŸŒ
hosthost:104.18.39.21bytes=220, ip=104.18.39.21
hosthost:52.182.143.215bytes=141,514, city=Des Moines, country=US, ip=52.182.143.215, org=Microsoft Corporation[41.6015, -93.6127, 0.0000] πŸŒ
hosthost:104.18.23.222bytes=13,297, ip=104.18.23.222
hosthost:52.110.6.13bytes=141, city=San Antonio, country=US, ip=52.110.6.13, org=Microsoft Corporation[29.4227, -98.4927, 0.0000] πŸŒ
hosthost:104.18.1.62bytes=321, ip=104.18.1.62
hosthost:192.168.1.165bytes=120, ip=192.168.1.165
hosthost:216.24.57.251bytes=228, city=, country=US, ip=216.24.57.251, org=Render[37.7510, -97.8220, 0.0000] πŸŒ
hosthost:167.235.217.196bytes=3,585, city=Falkenstein, country=DE, ip=167.235.217.196, org=Hetzner Online GmbH[50.4777, 12.3649, 0.0000] πŸŒ
hosthost:13.107.226.57bytes=121, city=, country=US, ip=13.107.226.57, org=Microsoft Corporation[37.7510, -97.8220, 0.0000] πŸŒ
hosthost:97.178.32.239bytes=3,492, city=Houston, country=US, ip=97.178.32.239, org=Verizon Business[29.8284, -95.4696, 0.0000] πŸŒ
hosthost:192.200.0.112bytes=1,924, city=, country=CA, ip=192.200.0.112, org=Amazon.com, Inc.[43.6319, -79.3716, 0.0000] πŸŒ
hosthost:23.219.160.5bytes=9,890, city=Houston, country=US, ip=23.219.160.5, org=Akamai International B.V.[29.7539, -95.3590, 0.0000] πŸŒ
hosthost:192.168.1.1bytes=2,087, ip=192.168.1.1
hosthost:162.159.128.61bytes=321, ip=162.159.128.61
hosthost:172.18.0.1bytes=498, ip=172.18.0.1
hosthost:23.213.232.172bytes=306, city=Dallas, country=US, ip=23.213.232.172, org=Akamai International B.V.[32.7797, -96.8022, 0.0000] πŸŒ
hosthost:151.101.114.172bytes=893, city=Dallas, country=US, ip=151.101.114.172, org=Fastly, Inc.[32.7797, -96.8022, 0.0000] πŸŒ
hosthost:192.73.243.135bytes=156, city=Miami, country=US, ip=192.73.243.135, org=NetActuate, Inc[25.7701, -80.1928, 0.0000] πŸŒ
hosthost:216.239.32.223bytes=298, city=, country=US, ip=216.239.32.223, org=Google LLC[37.7510, -97.8220, 0.0000] πŸŒ
hosthost:192.73.244.245bytes=156, city=Los Angeles, country=US, ip=192.73.244.245, org=NetActuate, Inc[34.0544, -118.2440, 0.0000] πŸŒ
hosthost:172.19.0.1bytes=498, ip=172.19.0.1
hosthost:172.64.151.22bytes=321, ip=172.64.151.22
hosthost:135.234.174.40bytes=121, city=Washington, country=US, ip=135.234.174.40, org=Microsoft Corporation[38.7095, -78.1539, 0.0000] πŸŒ
hosthost:216.24.57.7bytes=228, city=, country=US, ip=216.24.57.7, org=Render[37.7510, -97.8220, 0.0000] πŸŒ
hosthost:104.18.36.216bytes=321, ip=104.18.36.216
hosthost:150.171.28.10bytes=121, city=, country=US, ip=150.171.28.10, org=Microsoft Corporation[37.7510, -97.8220, 0.0000] πŸŒ
hosthost:209.177.158.246bytes=156, city=Chicago, country=US, ip=209.177.158.246, org=NetActuate, Inc[41.8835, -87.6305, 0.0000] πŸŒ
hosthost:192.168.1.185bytes=3,585, ip=192.168.1.185
hosthost:104.18.32.47bytes=11,687, ip=104.18.32.47
hosthost:104.208.203.89bytes=441, city=Boydton, country=US, ip=104.208.203.89, org=Microsoft Corporation[36.6694, -78.3877, 0.0000] πŸŒ
hosthost:34.111.31.13bytes=121, city=Kansas City, country=US, ip=34.111.31.13, org=Google LLC[39.1027, -94.5778, 0.0000] πŸŒ
hosthost:104.18.22.222bytes=1,002, ip=104.18.22.222
hosthost:199.165.136.100bytes=1,951, city=, country=CA, ip=199.165.136.100, org=Amazon.com, Inc.[43.6319, -79.3716, 0.0000] πŸŒ
hosthost:151.101.113.140bytes=121, city=Dallas, country=US, ip=151.101.113.140, org=Fastly, Inc.[32.7797, -96.8022, 0.0000] πŸŒ
hosthost:142.250.113.95bytes=8,541, city=, country=US, ip=142.250.113.95, org=Google LLC[37.7510, -97.8220, 0.0000] πŸŒ
hosthost:142.250.115.95bytes=1,532, city=, country=US, ip=142.250.115.95, org=Google LLC[37.7510, -97.8220, 0.0000] πŸŒ
hosthost:172.29.16.1bytes=498, ip=172.29.16.1
hosthost:224.0.0.22bytes=120, ip=224.0.0.22
hosthost:192.73.248.83bytes=30,133, city=Dallas, country=US, ip=192.73.248.83, org=NetActuate, Inc[32.7797, -96.8022, 0.0000] πŸŒ
hosthost:172.17.0.1bytes=498, ip=172.17.0.1
hosthost:151.101.112.217bytes=121, city=Dallas, country=US, ip=151.101.112.217, org=Fastly, Inc.[32.7797, -96.8022, 0.0000] πŸŒ
hosthost:76.76.21.22bytes=121, city=Walnut, country=US, ip=76.76.21.22, org=Amazon.com, Inc.[34.0233, -117.8512, 0.0000] πŸŒ
hosthost:20.62.59.32bytes=422, city=Boydton, country=US, ip=20.62.59.32, org=Microsoft Corporation[36.6694, -78.3877, 0.0000] πŸŒ
hosthost:209.177.156.94bytes=156, city=Dallas, country=US, ip=209.177.156.94, org=NetActuate, Inc[32.7797, -96.8022, 0.0000] πŸŒ
hosthost:35.190.80.1bytes=121, city=, country=US, ip=35.190.80.1, org=Google LLC[37.7510, -97.8220, 0.0000] πŸŒ
http_hosthttp_host:ctldl.windowsupdate.comhost=ctldl.windowsupdate.com
orgorg:Akamai International B.V.name=Akamai International B.V.
orgorg:Fastly, Inc.name=Fastly, Inc.
orgorg:Hetzner Online GmbHname=Hetzner Online GmbH
orgorg:Amazon.com, Inc.name=Amazon.com, Inc.
orgorg:Rendername=Render
orgorg:Google LLCname=Google LLC
orgorg:NetActuate, Incname=NetActuate, Inc
orgorg:Microsoft Corporationname=Microsoft Corporation
orgorg:Verizon Businessname=Verizon Business
pcap_artifactPCAP:cap_05182026_430pmCST:aee251eecdd8file_size=363,452, filename=cap_05182026_430pmCST.pcapng, ingested_at=2026-05-18T21:41:28.697945+00:00
port_hubport:udp:5351port=5,351, proto=udp
port_hubport:tcp:61509port=61,509, proto=tcp
port_hubport:udp:3478port=3,478, proto=udp
port_hubport:tcp:58457port=58,457, proto=tcp
port_hubport:udp:60920port=60,920, proto=udp
port_hubport:tcp:55880port=55,880, proto=tcp
port_hubport:tcp:54629port=54,629, proto=tcp
port_hubport:tcp:443port=443, proto=tcp
port_hubport:udp:443port=443, proto=udp
port_hubport:udp:41641port=41,641, proto=udp
port_hubport:tcp:52640port=52,640, proto=tcp
port_hubport:tcp:51146port=51,146, proto=tcp
port_hubport:tcp:51966port=51,966, proto=tcp
port_hubport:tcp:52133port=52,133, proto=tcp
port_hubport:tcp:80port=80, proto=tcp
port_hubport:tcp:58631port=58,631, proto=tcp
port_hubport:tcp:54986port=54,986, proto=tcp
port_hubport:udp:31036port=31,036, proto=udp
port_hubport:udp:52243port=52,243, proto=udp
port_hubport:tcp:62104port=62,104, proto=tcp
port_hubport:udp:44244port=44,244, proto=udp
port_hubport:udp:1050port=1,050, proto=udp
port_hubport:tcp:51049port=51,049, proto=tcp
port_hubport:tcp:46407port=46,407, proto=tcp
port_hubport:tcp:43844port=43,844, proto=tcp
port_hubport:tcp:51645port=51,645, proto=tcp
port_hubport:udp:11130port=11,130, proto=udp
port_hubport:udp:53port=53, proto=udp
protocol_eventpe:dns:SESSION-58f9cafe500f64adevent_type=DNS_EXCHANGE, query_count=14, session=SESSION-58f9cafe500f64ad
protocol_eventpe:tls:SESSION-b7d90a2138968fa3event_type=TLS_SESSION, packet_count=115, session=SESSION-b7d90a2138968fa3
protocol_eventpe:tls:SESSION-de97a19f0937505cevent_type=TLS_SESSION, packet_count=5, session=SESSION-de97a19f0937505c
protocol_eventpe:tls:SESSION-e53f703ab7b48a77event_type=TLS_SESSION, packet_count=3, session=SESSION-e53f703ab7b48a77
protocol_eventpe:tls:SESSION-5673cdc8e15ecc28event_type=TLS_SESSION, packet_count=5, session=SESSION-5673cdc8e15ecc28
protocol_eventpe:tls:SESSION-05305b96b26cdffdevent_type=TLS_SESSION, packet_count=3, session=SESSION-05305b96b26cdffd
protocol_eventpe:tls:SESSION-787a71cfd2c6f769event_type=TLS_SESSION, packet_count=5, session=SESSION-787a71cfd2c6f769
protocol_eventpe:tls:SESSION-e565a4fbf5cff09bevent_type=TLS_SESSION, packet_count=13, session=SESSION-e565a4fbf5cff09b
protocol_eventpe:tls:SESSION-934baa2aae663cebevent_type=TLS_SESSION, packet_count=2, session=SESSION-934baa2aae663ceb
protocol_eventpe:tls:SESSION-cbcc97483386b4f3event_type=TLS_SESSION, packet_count=21, session=SESSION-cbcc97483386b4f3
protocol_eventpe:tls:SESSION-c8f5f362e7c0c5c8event_type=TLS_SESSION, packet_count=3, session=SESSION-c8f5f362e7c0c5c8
protocol_eventpe:tls:SESSION-2014bf32e6dab59eevent_type=TLS_SESSION, packet_count=2, session=SESSION-2014bf32e6dab59e
protocol_eventpe:tls:SESSION-99947e3aab494326event_type=TLS_SESSION, packet_count=2, session=SESSION-99947e3aab494326
protocol_eventpe:tls:SESSION-055fd962754012c2event_type=TLS_SESSION, packet_count=4, session=SESSION-055fd962754012c2
protocol_eventpe:tls:SESSION-9c845bfb2b534b59event_type=TLS_SESSION, packet_count=11, session=SESSION-9c845bfb2b534b59
protocol_eventpe:tls:SESSION-bc4350b5c6d66f3fevent_type=TLS_SESSION, packet_count=2, session=SESSION-bc4350b5c6d66f3f
protocol_eventpe:tls:SESSION-184b3698d564c9c7event_type=TLS_SESSION, packet_count=3, session=SESSION-184b3698d564c9c7
protocol_eventpe:syn:SESSION-06fade4febc8462ccount=2, event_type=TCP_SYN, session=SESSION-06fade4febc8462c
protocol_eventpe:syn:SESSION-81e5b5be161de125count=2, event_type=TCP_SYN, session=SESSION-81e5b5be161de125
protocol_eventpe:syn:SESSION-9b68d4601d0ccd30count=2, event_type=TCP_SYN, session=SESSION-9b68d4601d0ccd30
protocol_eventpe:dns:SESSION-68666b77cce29d40event_type=DNS_EXCHANGE, query_count=6, session=SESSION-68666b77cce29d40
protocol_eventpe:tls:SESSION-36cd4459caa078a9event_type=TLS_SESSION, packet_count=2, session=SESSION-36cd4459caa078a9
protocol_eventpe:tls:SESSION-e881aa680da5dbf3event_type=TLS_SESSION, packet_count=2, session=SESSION-e881aa680da5dbf3
protocol_eventpe:syn:SESSION-8394aca80c2a0790count=2, event_type=TCP_SYN, session=SESSION-8394aca80c2a0790
protocol_eventpe:tls:SESSION-65a9e51617aa2712event_type=TLS_SESSION, packet_count=6, session=SESSION-65a9e51617aa2712
protocol_eventpe:tls:SESSION-9dab8edd40d14d9devent_type=TLS_SESSION, packet_count=3, session=SESSION-9dab8edd40d14d9d
protocol_eventpe:tls:SESSION-348feef1c6ca6285event_type=TLS_SESSION, packet_count=2, session=SESSION-348feef1c6ca6285
protocol_eventpe:dns:SESSION-08bfd8721a383a39event_type=DNS_EXCHANGE, query_count=4, session=SESSION-08bfd8721a383a39
protocol_eventpe:tls:SESSION-7b2b00e0ceb88c09event_type=TLS_SESSION, packet_count=6, session=SESSION-7b2b00e0ceb88c09
protocol_eventpe:tls:SESSION-741380b5a9a3a6c7event_type=TLS_SESSION, packet_count=5, session=SESSION-741380b5a9a3a6c7
protocol_eventpe:syn:SESSION-83d0b20751c23f69count=2, event_type=TCP_SYN, session=SESSION-83d0b20751c23f69
protocol_eventpe:tls:SESSION-e6ad21d692182871event_type=TLS_SESSION, packet_count=25, session=SESSION-e6ad21d692182871
protocol_eventpe:tls:SESSION-8394aca80c2a0790event_type=TLS_SESSION, packet_count=90, session=SESSION-8394aca80c2a0790
protocol_eventpe:tls:SESSION-04dc5a38b6cabcefevent_type=TLS_SESSION, packet_count=4, session=SESSION-04dc5a38b6cabcef
protocol_eventpe:tls:SESSION-8fd6ad39adf47a18event_type=TLS_SESSION, packet_count=5, session=SESSION-8fd6ad39adf47a18
protocol_eventpe:syn:SESSION-21bfec774060aafbcount=2, event_type=TCP_SYN, session=SESSION-21bfec774060aafb
protocol_eventpe:tls:SESSION-a019cb392bc23a7aevent_type=TLS_SESSION, packet_count=4, session=SESSION-a019cb392bc23a7a
protocol_eventpe:tls:SESSION-0e59fb5fe4c720dfevent_type=TLS_SESSION, packet_count=15, session=SESSION-0e59fb5fe4c720df
protocol_eventpe:tls:SESSION-d146af26ba988e06event_type=TLS_SESSION, packet_count=18, session=SESSION-d146af26ba988e06
protocol_eventpe:syn:SESSION-cbcc97483386b4f3count=2, event_type=TCP_SYN, session=SESSION-cbcc97483386b4f3
protocol_eventpe:tls:SESSION-06fade4febc8462cevent_type=TLS_SESSION, packet_count=21, session=SESSION-06fade4febc8462c
protocol_eventpe:tls:SESSION-9c85e6a530e7f20fevent_type=TLS_SESSION, packet_count=5, session=SESSION-9c85e6a530e7f20f
protocol_eventpe:tls:SESSION-200a1edeb5081c1bevent_type=TLS_SESSION, packet_count=2, session=SESSION-200a1edeb5081c1b
protocol_eventpe:tls:SESSION-b7338ba843b2dafaevent_type=TLS_SESSION, packet_count=96, session=SESSION-b7338ba843b2dafa
protocol_eventpe:tls:SESSION-dabcbf693ac9fbefevent_type=TLS_SESSION, packet_count=2, session=SESSION-dabcbf693ac9fbef
protocol_eventpe:tls:SESSION-423d6f8fa2a9f7bcevent_type=TLS_SESSION, packet_count=5, session=SESSION-423d6f8fa2a9f7bc
protocol_eventpe:tls:SESSION-502ccca87ddbbb24event_type=TLS_SESSION, packet_count=2, session=SESSION-502ccca87ddbbb24
protocol_eventpe:tls:SESSION-441bb1af5ec88ffbevent_type=TLS_SESSION, packet_count=2, session=SESSION-441bb1af5ec88ffb
protocol_eventpe:syn:SESSION-d146af26ba988e06count=2, event_type=TCP_SYN, session=SESSION-d146af26ba988e06
protocol_eventpe:tls:SESSION-ea1d23994577309aevent_type=TLS_SESSION, packet_count=14, session=SESSION-ea1d23994577309a
protocol_eventpe:tls:SESSION-c4d9c40a7fec56beevent_type=TLS_SESSION, packet_count=2, session=SESSION-c4d9c40a7fec56be
protocol_eventpe:tls:SESSION-fa034e5132aecf5bevent_type=TLS_SESSION, packet_count=2, session=SESSION-fa034e5132aecf5b
servicesvc:httpsname=https
servicesvc:dnsname=dns
servicesvc:httpname=http
sessionSESSION-e53f703ab7b48a77dst_ip=199.165.136.100, dst_port=443, duration_sec=0.08, end_time=1,779,139,830.569, expected_protocol=https, packet_count=3, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=45,590, start_time=1,779,139,830.489, tcp_flags=P,A, time_bucket=1,779,139,830, total_bytes=660, window_sec=30
sessionSESSION-83d0b20751c23f69dst_ip=192.168.1.1, dst_port=46,407, duration_sec=0.02, end_time=1,779,139,815.162, expected_protocol=unregistered:46407, packet_count=10, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=192.168.1.185, src_port=45,124, start_time=1,779,139,815.137, tcp_flags=S,P,A,F, time_bucket=1,779,139,800, total_bytes=1,782, window_sec=30
sessionSESSION-9dab8edd40d14d9ddst_ip=192.168.1.185, dst_port=58,457, duration_sec=0.04, end_time=1,779,139,831.127, expected_protocol=unregistered:58457, packet_count=3, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=104.18.39.21, src_port=443, start_time=1,779,139,831.082, tcp_flags=P,A, time_bucket=1,779,139,830, total_bytes=220, window_sec=30
sessionSESSION-e6729d0ebc579395dst_ip=97.178.32.239, dst_port=41,641, duration_sec=10.55, end_time=1,779,139,824.498, expected_protocol=unregistered:41641, packet_count=3, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=44,244, start_time=1,779,139,813.948, tcp_flags=, time_bucket=1,779,139,800, total_bytes=498, window_sec=30
sessionSESSION-2014bf32e6dab59edst_ip=151.101.113.140, dst_port=443, duration_sec=0.03, end_time=1,779,139,829.188, expected_protocol=https, packet_count=2, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=61,648, start_time=1,779,139,829.157, tcp_flags=A, time_bucket=1,779,139,800, total_bytes=121, window_sec=30
sessionSESSION-200a1edeb5081c1bdst_ip=192.168.1.185, dst_port=54,629, duration_sec=0.05, end_time=1,779,139,824.265, expected_protocol=unregistered:54629, packet_count=2, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=52.110.6.13, src_port=443, start_time=1,779,139,824.216, tcp_flags=P,A, time_bucket=1,779,139,800, total_bytes=141, window_sec=30
sessionSESSION-604f49b2ccac8492dst_ip=97.178.32.239, dst_port=52,243, duration_sec=10.55, end_time=1,779,139,824.457, expected_protocol=unregistered:52243, packet_count=3, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=41,641, start_time=1,779,139,813.904, tcp_flags=, time_bucket=1,779,139,800, total_bytes=498, window_sec=30
sessionSESSION-5419af02605f5da4dst_ip=97.178.32.239, dst_port=41,641, duration_sec=10.55, end_time=1,779,139,824.457, expected_protocol=unregistered:41641, packet_count=3, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=41,641, start_time=1,779,139,813.904, tcp_flags=, time_bucket=1,779,139,800, total_bytes=498, window_sec=30
sessionSESSION-741380b5a9a3a6c7dst_ip=192.168.1.185, dst_port=62,104, duration_sec=0.03, end_time=1,779,139,825.023, expected_protocol=unregistered:62104, packet_count=5, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=172.64.151.22, src_port=443, start_time=1,779,139,824.993, tcp_flags=P,F,A, time_bucket=1,779,139,800, total_bytes=321, window_sec=30
sessionSESSION-184b3698d564c9c7dst_ip=192.168.1.185, dst_port=58,631, duration_sec=0.03, end_time=1,779,139,818.715, expected_protocol=unregistered:58631, packet_count=3, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=216.24.57.7, src_port=443, start_time=1,779,139,818.689, tcp_flags=P,A, time_bucket=1,779,139,800, total_bytes=228, window_sec=30
sessionSESSION-e565a4fbf5cff09bdst_ip=192.73.248.83, dst_port=443, duration_sec=0.77, end_time=1,779,139,832.674, expected_protocol=https, packet_count=13, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=49,982, start_time=1,779,139,831.906, tcp_flags=P,A, time_bucket=1,779,139,830, total_bytes=2,238, window_sec=30
sessionSESSION-858ec5d25a7b6232dst_ip=97.178.32.239, dst_port=11,130, duration_sec=10.55, end_time=1,779,139,824.458, expected_protocol=unregistered:11130, packet_count=3, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=41,641, start_time=1,779,139,813.904, tcp_flags=, time_bucket=1,779,139,800, total_bytes=498, window_sec=30
sessionSESSION-bcd07bc8e00bd126dst_ip=209.177.158.246, dst_port=3,478, duration_sec=0.05, end_time=1,779,139,814.853, expected_protocol=unregistered:3478, packet_count=2, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=44,244, start_time=1,779,139,814.8, tcp_flags=, time_bucket=1,779,139,800, total_bytes=156, window_sec=30
sessionSESSION-c4d9c40a7fec56bedst_ip=135.234.174.40, dst_port=443, duration_sec=0.06, end_time=1,779,139,824.108, expected_protocol=https, packet_count=2, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=51,136, start_time=1,779,139,824.046, tcp_flags=A, time_bucket=1,779,139,800, total_bytes=121, window_sec=30
sessionSESSION-8fd6ad39adf47a18dst_ip=192.168.1.185, dst_port=55,880, duration_sec=0.03, end_time=1,779,139,823.793, expected_protocol=unregistered:55880, packet_count=5, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=104.18.36.216, src_port=443, start_time=1,779,139,823.759, tcp_flags=P,F,A, time_bucket=1,779,139,800, total_bytes=321, window_sec=30
sessionSESSION-9c845bfb2b534b59dst_ip=150.171.28.10, dst_port=443, duration_sec=0.19, end_time=1,779,139,833.641, expected_protocol=https, packet_count=11, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=62,432, start_time=1,779,139,833.456, tcp_flags=P,A, time_bucket=1,779,139,830, total_bytes=3,906, window_sec=30
sessionSESSION-329be171c0b80b92dst_ip=172.29.16.1, dst_port=41,641, duration_sec=10.55, end_time=1,779,139,824.498, expected_protocol=unregistered:41641, packet_count=3, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=44,244, start_time=1,779,139,813.948, tcp_flags=, time_bucket=1,779,139,800, total_bytes=498, window_sec=30
sessionSESSION-787a71cfd2c6f769dst_ip=192.168.1.185, dst_port=61,509, duration_sec=0.04, end_time=1,779,139,823.853, expected_protocol=unregistered:61509, packet_count=5, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=162.159.128.61, src_port=443, start_time=1,779,139,823.808, tcp_flags=P,F,A, time_bucket=1,779,139,800, total_bytes=321, window_sec=30
sessionSESSION-a019cb392bc23a7adst_ip=199.165.136.100, dst_port=443, duration_sec=0.17, end_time=1,779,139,831.279, expected_protocol=https, packet_count=4, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=57,514, start_time=1,779,139,831.111, tcp_flags=P,A, time_bucket=1,779,139,830, total_bytes=642, window_sec=30
sessionSESSION-81e5b5be161de125dst_ip=151.101.114.172, dst_port=80, duration_sec=0.15, end_time=1,779,139,820.515, expected_protocol=http, packet_count=7, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=192.168.1.185, src_port=57,908, start_time=1,779,139,820.368, tcp_flags=S,P,A, time_bucket=1,779,139,800, total_bytes=893, window_sec=30
sessionSESSION-f32643b41a201d5bdst_ip=209.177.158.246, dst_port=3,478, duration_sec=0.05, end_time=1,779,139,827.583, expected_protocol=unregistered:3478, packet_count=2, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=41,641, start_time=1,779,139,827.529, tcp_flags=, time_bucket=1,779,139,800, total_bytes=156, window_sec=30
sessionSESSION-c8f5f362e7c0c5c8dst_ip=192.168.1.185, dst_port=51,049, duration_sec=0.04, end_time=1,779,139,828.252, expected_protocol=unregistered:51049, packet_count=3, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=216.24.57.251, src_port=443, start_time=1,779,139,828.217, tcp_flags=P,A, time_bucket=1,779,139,800, total_bytes=228, window_sec=30
sessionSESSION-423d6f8fa2a9f7bcdst_ip=192.168.1.185, dst_port=51,966, duration_sec=0.03, end_time=1,779,139,828.883, expected_protocol=unregistered:51966, packet_count=5, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=23.213.232.172, src_port=443, start_time=1,779,139,828.857, tcp_flags=P,F,A, time_bucket=1,779,139,800, total_bytes=306, window_sec=30
sessionSESSION-b7d90a2138968fa3dst_ip=192.168.1.185, dst_port=43,844, duration_sec=14.67, end_time=1,779,139,828.613, expected_protocol=unregistered:43844, packet_count=115, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=209.177.156.94, src_port=443, start_time=1,779,139,813.948, tcp_flags=P,A, time_bucket=1,779,139,800, total_bytes=32,594, window_sec=30
sessionSESSION-e66fd8e05921da5ddst_ip=172.18.0.1, dst_port=44,244, duration_sec=10.55, end_time=1,779,139,824.458, expected_protocol=unregistered:44244, packet_count=3, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=41,641, start_time=1,779,139,813.904, tcp_flags=, time_bucket=1,779,139,800, total_bytes=498, window_sec=30
sessionSESSION-36cd4459caa078a9dst_ip=135.234.174.40, dst_port=443, duration_sec=0.07, end_time=1,779,139,827.293, expected_protocol=https, packet_count=2, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=51,820, start_time=1,779,139,827.225, tcp_flags=A, time_bucket=1,779,139,800, total_bytes=121, window_sec=30
sessionSESSION-e881aa680da5dbf3dst_ip=151.101.112.217, dst_port=443, duration_sec=0.04, end_time=1,779,139,829.598, expected_protocol=https, packet_count=2, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=50,174, start_time=1,779,139,829.56, tcp_flags=A, time_bucket=1,779,139,800, total_bytes=121, window_sec=30
sessionSESSION-7dbcb4428a9e5e71dst_ip=209.177.156.94, dst_port=3,478, duration_sec=0.04, end_time=1,779,139,814.838, expected_protocol=unregistered:3478, packet_count=2, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=44,244, start_time=1,779,139,814.8, tcp_flags=, time_bucket=1,779,139,800, total_bytes=156, window_sec=30
sessionSESSION-1f115942b61afe54dst_ip=192.73.244.245, dst_port=3,478, duration_sec=0.07, end_time=1,779,139,827.597, expected_protocol=unregistered:3478, packet_count=2, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=41,641, start_time=1,779,139,827.529, tcp_flags=, time_bucket=1,779,139,800, total_bytes=156, window_sec=30
sessionSESSION-1ea83345da6e2df0dst_ip=224.0.0.22, duration_sec=0.13, end_time=1,779,139,833.109, expected_protocol=unregistered:0, packet_count=2, proto=OTHER, protocol_anomaly_score=0, protocol_violations=, protocols=OTHER, src_ip=192.168.1.165, start_time=1,779,139,832.977, tcp_flags=, time_bucket=1,779,139,830, total_bytes=120, window_sec=30
sessionSESSION-0e59fb5fe4c720dfdst_ip=192.168.1.185, dst_port=43,844, duration_sec=0.69, end_time=1,779,139,832.637, expected_protocol=unregistered:43844, packet_count=15, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=209.177.156.94, src_port=443, start_time=1,779,139,831.947, tcp_flags=P,A, time_bucket=1,779,139,830, total_bytes=2,508, window_sec=30
sessionSESSION-65a9e51617aa2712dst_ip=199.165.136.100, dst_port=443, duration_sec=4.53, end_time=1,779,139,821.588, expected_protocol=https, packet_count=6, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=45,590, start_time=1,779,139,817.062, tcp_flags=P,A, time_bucket=1,779,139,800, total_bytes=1,951, window_sec=30
sessionSESSION-e86e0a049372cc85dst_ip=142.250.113.95, dst_port=443, duration_sec=0.33, end_time=1,779,139,821.155, expected_protocol=quic, packet_count=20, proto=UDP, protocol_anomaly_score=0.4, protocol_violations=missing_tls,risk_port, protocols=UDP, src_ip=192.168.1.185, src_port=55,836, start_time=1,779,139,820.821, tcp_flags=, time_bucket=1,779,139,800, total_bytes=8,541, window_sec=30
sessionSESSION-f8dc5b0051ee4914dst_ip=192.168.1.1, duration_sec=12.77, end_time=1,779,139,827.691, expected_protocol=unregistered:0, packet_count=5, proto=ICMP, protocol_anomaly_score=0, protocol_violations=, protocols=ICMP, src_ip=192.168.1.185, start_time=1,779,139,814.917, tcp_flags=, time_bucket=1,779,139,800, total_bytes=1,621, window_sec=30
sessionSESSION-8c7ddbb6fe26a9a9dst_ip=192.168.1.185, dst_port=60,920, duration_sec=10.01, end_time=1,779,139,829.032, expected_protocol=unregistered:60920, packet_count=4, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=216.239.32.223, src_port=443, start_time=1,779,139,819.023, tcp_flags=, time_bucket=1,779,139,800, total_bytes=298, window_sec=30
sessionSESSION-68666b77cce29d40dst_ip=192.168.1.1, dst_port=53, duration_sec=4.54, end_time=1,779,139,820.366, expected_protocol=dns, packet_count=6, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=59,921, start_time=1,779,139,815.826, tcp_flags=, time_bucket=1,779,139,800, total_bytes=822, window_sec=30
sessionSESSION-06fade4febc8462cdst_ip=104.18.23.222, dst_port=443, duration_sec=0.42, end_time=1,779,139,827.943, expected_protocol=https, packet_count=21, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=192.168.1.185, src_port=51,621, start_time=1,779,139,827.526, tcp_flags=S,P,A, time_bucket=1,779,139,800, total_bytes=13,297, window_sec=30
sessionSESSION-e6ad21d692182871dst_ip=199.165.136.100, dst_port=443, duration_sec=15.84, end_time=1,779,139,829.575, expected_protocol=https, packet_count=25, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=57,514, start_time=1,779,139,813.737, tcp_flags=P,A, time_bucket=1,779,139,800, total_bytes=5,086, window_sec=30
sessionSESSION-08bfd8721a383a39dst_ip=192.168.1.1, dst_port=53, duration_sec=0.18, end_time=1,779,139,833.635, expected_protocol=dns, packet_count=4, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=55,743, start_time=1,779,139,833.456, tcp_flags=, time_bucket=1,779,139,830, total_bytes=410, window_sec=30
sessionSESSION-e5c653feb7de823fdst_ip=192.73.243.135, dst_port=3,478, duration_sec=0.06, end_time=1,779,139,814.863, expected_protocol=unregistered:3478, packet_count=2, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=44,244, start_time=1,779,139,814.8, tcp_flags=, time_bucket=1,779,139,800, total_bytes=156, window_sec=30
sessionSESSION-441bb1af5ec88ffbdst_ip=76.76.21.22, dst_port=443, duration_sec=0.03, end_time=1,779,139,829.733, expected_protocol=https, packet_count=2, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=58,156, start_time=1,779,139,829.699, tcp_flags=A, time_bucket=1,779,139,800, total_bytes=121, window_sec=30
sessionSESSION-8394aca80c2a0790dst_ip=52.182.143.215, dst_port=443, duration_sec=2.1, end_time=1,779,139,828.097, expected_protocol=https, packet_count=90, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=192.168.1.185, src_port=61,094, start_time=1,779,139,825.992, tcp_flags=S,P,A, time_bucket=1,779,139,800, total_bytes=141,514, window_sec=30
sessionSESSION-3cb87513d2c7904fdst_ip=192.168.1.1, dst_port=5,351, duration_sec=0.02, end_time=1,779,139,827.562, expected_protocol=unregistered:5351, packet_count=4, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=65,065, start_time=1,779,139,827.538, tcp_flags=, time_bucket=1,779,139,800, total_bytes=230, window_sec=30
sessionSESSION-21bfec774060aafbdst_ip=192.168.1.1, dst_port=46,407, duration_sec=0.07, end_time=1,779,139,815.138, expected_protocol=unregistered:46407, packet_count=10, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=192.168.1.185, src_port=45,114, start_time=1,779,139,815.064, tcp_flags=S,P,A,F, time_bucket=1,779,139,800, total_bytes=2,087, window_sec=30
sessionSESSION-7bf53771cd98ec17dst_ip=192.168.1.1, dst_port=5,351, duration_sec=0.13, end_time=1,779,139,814.917, expected_protocol=unregistered:5351, packet_count=4, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=45,439, start_time=1,779,139,814.79, tcp_flags=, time_bucket=1,779,139,800, total_bytes=218, window_sec=30
sessionSESSION-04dc5a38b6cabcefdst_ip=192.168.1.185, dst_port=54,986, duration_sec=0, end_time=1,779,139,828.507, expected_protocol=unregistered:54986, packet_count=4, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=167.235.217.196, src_port=443, start_time=1,779,139,828.503, tcp_flags=P,A, time_bucket=1,779,139,800, total_bytes=3,585, window_sec=30
sessionSESSION-1065a64ded6cc44cdst_ip=172.19.0.1, dst_port=44,244, duration_sec=10.55, end_time=1,779,139,824.458, expected_protocol=unregistered:44244, packet_count=3, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=41,641, start_time=1,779,139,813.904, tcp_flags=, time_bucket=1,779,139,800, total_bytes=498, window_sec=30
sessionSESSION-e0cdf80170e46e9edst_ip=142.250.115.95, dst_port=443, duration_sec=0.16, end_time=1,779,139,821.998, expected_protocol=quic, packet_count=21, proto=UDP, protocol_anomaly_score=0.4, protocol_violations=missing_tls,risk_port, protocols=UDP, src_ip=192.168.1.185, src_port=59,475, start_time=1,779,139,821.843, tcp_flags=, time_bucket=1,779,139,800, total_bytes=8,434, window_sec=30
sessionSESSION-055fd962754012c2dst_ip=104.208.203.89, dst_port=443, duration_sec=0.34, end_time=1,779,139,828.283, expected_protocol=https, packet_count=4, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=64,727, start_time=1,779,139,827.941, tcp_flags=P,A, time_bucket=1,779,139,800, total_bytes=441, window_sec=30
sessionSESSION-86bc6b9e53c222b0dst_ip=23.219.160.5, dst_port=443, duration_sec=1.45, end_time=1,779,139,815.348, expected_protocol=quic, packet_count=3, proto=UDP, protocol_anomaly_score=0.4, protocol_violations=missing_tls,risk_port, protocols=UDP, src_ip=192.168.1.185, src_port=62,877, start_time=1,779,139,813.899, tcp_flags=, time_bucket=1,779,139,800, total_bytes=245, window_sec=30
sessionSESSION-5673cdc8e15ecc28dst_ip=192.168.1.185, dst_port=54,986, duration_sec=0, end_time=1,779,139,830.263, expected_protocol=unregistered:54986, packet_count=5, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=167.235.217.196, src_port=443, start_time=1,779,139,830.263, tcp_flags=P,A, time_bucket=1,779,139,830, total_bytes=4,440, window_sec=30
sessionSESSION-99947e3aab494326dst_ip=192.168.1.185, dst_port=51,645, duration_sec=0.05, end_time=1,779,139,832.907, expected_protocol=unregistered:51645, packet_count=2, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=192.200.0.112, src_port=443, start_time=1,779,139,832.858, tcp_flags=P,A, time_bucket=1,779,139,830, total_bytes=193, window_sec=30
sessionSESSION-de97a19f0937505cdst_ip=192.168.1.185, dst_port=51,146, duration_sec=0.05, end_time=1,779,139,823.88, expected_protocol=unregistered:51146, packet_count=5, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=104.18.1.62, src_port=443, start_time=1,779,139,823.833, tcp_flags=P,F,A, time_bucket=1,779,139,800, total_bytes=321, window_sec=30
sessionSESSION-cbcc97483386b4f3dst_ip=104.18.32.47, dst_port=443, duration_sec=4.56, end_time=1,779,139,820.41, expected_protocol=https, packet_count=21, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=192.168.1.185, src_port=46,474, start_time=1,779,139,815.852, tcp_flags=S,P,A,F, time_bucket=1,779,139,800, total_bytes=11,687, window_sec=30
sessionSESSION-9b68d4601d0ccd30dst_ip=192.168.1.1, dst_port=46,407, duration_sec=0, end_time=1,779,139,815.064, expected_protocol=unregistered:46407, packet_count=12, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=192.168.1.185, src_port=45,112, start_time=1,779,139,815.061, tcp_flags=S,P,A,F, time_bucket=1,779,139,800, total_bytes=4,269, window_sec=30
sessionSESSION-fa034e5132aecf5bdst_ip=13.107.226.57, dst_port=443, duration_sec=0.05, end_time=1,779,139,825.808, expected_protocol=https, packet_count=2, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=65,238, start_time=1,779,139,825.755, tcp_flags=A, time_bucket=1,779,139,800, total_bytes=121, window_sec=30
sessionSESSION-dabcbf693ac9fbefdst_ip=150.171.28.10, dst_port=443, duration_sec=0.05, end_time=1,779,139,816.663, expected_protocol=https, packet_count=2, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=62,432, start_time=1,779,139,816.617, tcp_flags=A, time_bucket=1,779,139,800, total_bytes=121, window_sec=30
sessionSESSION-58f9cafe500f64addst_ip=192.168.1.1, dst_port=53, duration_sec=11.67, end_time=1,779,139,827.523, expected_protocol=dns, packet_count=14, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=55,743, start_time=1,779,139,815.85, tcp_flags=, time_bucket=1,779,139,800, total_bytes=1,712, window_sec=30
sessionSESSION-d7f6ed06cf3ab18bdst_ip=192.168.1.185, duration_sec=0.04, end_time=1,779,139,831.948, expected_protocol=unregistered:0, packet_count=6, proto=ICMP, protocol_anomaly_score=0.4, protocol_violations=constant_size_c2, protocols=ICMP, src_ip=97.178.32.239, start_time=1,779,139,831.907, tcp_flags=, time_bucket=1,779,139,830, total_bytes=1,164, window_sec=30
sessionSESSION-934baa2aae663cebdst_ip=151.101.113.140, dst_port=443, duration_sec=0.05, end_time=1,779,139,829.427, expected_protocol=https, packet_count=2, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=60,726, start_time=1,779,139,829.374, tcp_flags=A, time_bucket=1,779,139,800, total_bytes=121, window_sec=30
sessionSESSION-e25097cf84c7b988dst_ip=97.178.32.239, dst_port=1,050, duration_sec=10.55, end_time=1,779,139,824.457, expected_protocol=unregistered:1050, packet_count=3, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=41,641, start_time=1,779,139,813.904, tcp_flags=, time_bucket=1,779,139,800, total_bytes=498, window_sec=30
sessionSESSION-9c85e6a530e7f20fdst_ip=192.200.0.112, dst_port=443, duration_sec=0.17, end_time=1,779,139,815.353, expected_protocol=https, packet_count=5, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=44,420, start_time=1,779,139,815.185, tcp_flags=P,A, time_bucket=1,779,139,800, total_bytes=1,924, window_sec=30
sessionSESSION-1835bee014d5b0b3dst_ip=172.17.0.1, dst_port=44,244, duration_sec=10.55, end_time=1,779,139,824.458, expected_protocol=unregistered:44244, packet_count=3, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=41,641, start_time=1,779,139,813.904, tcp_flags=, time_bucket=1,779,139,800, total_bytes=498, window_sec=30
sessionSESSION-4cf06bd9f9c07bb4dst_ip=97.178.32.239, dst_port=31,036, duration_sec=10.55, end_time=1,779,139,824.458, expected_protocol=unregistered:31036, packet_count=3, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=41,641, start_time=1,779,139,813.904, tcp_flags=, time_bucket=1,779,139,800, total_bytes=498, window_sec=30
sessionSESSION-22420a928847cfaddst_ip=192.168.1.1, dst_port=5,351, duration_sec=0.13, end_time=1,779,139,814.936, expected_protocol=unregistered:5351, packet_count=4, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=45,706, start_time=1,779,139,814.81, tcp_flags=, time_bucket=1,779,139,800, total_bytes=230, window_sec=30
sessionSESSION-b7338ba843b2dafadst_ip=192.73.248.83, dst_port=443, duration_sec=14.66, end_time=1,779,139,828.562, expected_protocol=https, packet_count=96, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=49,982, start_time=1,779,139,813.904, tcp_flags=P,A, time_bucket=1,779,139,800, total_bytes=30,133, window_sec=30
sessionSESSION-65e185b6eab54d6adst_ip=192.168.1.1, dst_port=5,351, duration_sec=0.15, end_time=1,779,139,827.691, expected_protocol=unregistered:5351, packet_count=4, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=65,066, start_time=1,779,139,827.54, tcp_flags=, time_bucket=1,779,139,800, total_bytes=218, window_sec=30
sessionSESSION-716de9787a03c45edst_ip=23.219.160.5, dst_port=443, duration_sec=8.35, end_time=1,779,139,823.758, expected_protocol=quic, packet_count=40, proto=UDP, protocol_anomaly_score=0.4, protocol_violations=missing_tls,risk_port, protocols=UDP, src_ip=192.168.1.185, src_port=60,418, start_time=1,779,139,815.405, tcp_flags=, time_bucket=1,779,139,800, total_bytes=9,890, window_sec=30
sessionSESSION-17e440ba96a7a7b5dst_ip=142.250.115.95, dst_port=443, duration_sec=5.59, end_time=1,779,139,822.073, expected_protocol=quic, packet_count=11, proto=UDP, protocol_anomaly_score=0.4, protocol_violations=missing_tls,risk_port, protocols=UDP, src_ip=192.168.1.185, src_port=57,835, start_time=1,779,139,816.478, tcp_flags=, time_bucket=1,779,139,800, total_bytes=1,532, window_sec=30
sessionSESSION-05305b96b26cdffddst_ip=192.168.1.185, dst_port=52,640, duration_sec=0.07, end_time=1,779,139,827.193, expected_protocol=unregistered:52640, packet_count=3, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=104.18.39.21, src_port=443, start_time=1,779,139,827.119, tcp_flags=P,A, time_bucket=1,779,139,800, total_bytes=220, window_sec=30
sessionSESSION-d146af26ba988e06dst_ip=104.18.32.47, dst_port=443, duration_sec=4.3, end_time=1,779,139,829.989, expected_protocol=https, packet_count=18, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=192.168.1.185, src_port=44,698, start_time=1,779,139,825.688, tcp_flags=S,P,A,F, time_bucket=1,779,139,800, total_bytes=11,087, window_sec=30
sessionSESSION-2681df7af5f78270dst_ip=192.168.1.185, duration_sec=10.59, end_time=1,779,139,824.499, expected_protocol=unregistered:0, packet_count=18, proto=ICMP, protocol_anomaly_score=0.4, protocol_violations=constant_size_c2, protocols=ICMP, src_ip=97.178.32.239, start_time=1,779,139,813.905, tcp_flags=, time_bucket=1,779,139,800, total_bytes=3,492, window_sec=30
sessionSESSION-bc4350b5c6d66f3fdst_ip=34.111.31.13, dst_port=443, duration_sec=0.03, end_time=1,779,139,830.188, expected_protocol=https, packet_count=2, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=61,825, start_time=1,779,139,830.154, tcp_flags=A, time_bucket=1,779,139,830, total_bytes=121, window_sec=30
sessionSESSION-ce6603a48a5c4c37dst_ip=23.219.160.5, dst_port=443, duration_sec=0.09, end_time=1,779,139,830.263, expected_protocol=quic, packet_count=2, proto=UDP, protocol_anomaly_score=0.4, protocol_violations=missing_tls,risk_port, protocols=UDP, src_ip=192.168.1.185, src_port=60,418, start_time=1,779,139,830.169, tcp_flags=, time_bucket=1,779,139,830, total_bytes=137, window_sec=30
sessionSESSION-7b2b00e0ceb88c09dst_ip=20.62.59.32, dst_port=443, duration_sec=13.14, end_time=1,779,139,827.119, expected_protocol=https, packet_count=6, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=64,848, start_time=1,779,139,813.976, tcp_flags=P,A, time_bucket=1,779,139,800, total_bytes=422, window_sec=30
sessionSESSION-ea1d23994577309adst_ip=192.168.1.185, dst_port=52,133, duration_sec=8.09, end_time=1,779,139,825.978, expected_protocol=unregistered:52133, packet_count=14, proto=TCP, protocol_anomaly_score=0, protocol_violations=, protocols=TCP, src_ip=104.18.22.222, src_port=443, start_time=1,779,139,817.888, tcp_flags=P,F,A, time_bucket=1,779,139,800, total_bytes=1,002, window_sec=30
sessionSESSION-10cf97843d85c279dst_ip=209.177.156.94, dst_port=3,478, duration_sec=0.03, end_time=1,779,139,827.562, expected_protocol=unregistered:3478, packet_count=2, proto=UDP, protocol_anomaly_score=0, protocol_violations=, protocols=UDP, src_ip=192.168.1.185, src_port=41,641, start_time=1,779,139,827.529, tcp_flags=, time_bucket=1,779,139,800, total_bytes=156, window_sec=30
sessionSESSION-348feef1c6ca6285dst_ip=151.101.113.140, dst_port=443, duration_sec=0.06, end_time=1,779,139,829.463, expected_protocol=https, packet_count=2, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=52,662, start_time=1,779,139,829.405, tcp_flags=A, time_bucket=1,779,139,800, total_bytes=121, window_sec=30
sessionSESSION-502ccca87ddbbb24dst_ip=35.190.80.1, dst_port=443, duration_sec=0.03, end_time=1,779,139,826.633, expected_protocol=https, packet_count=2, proto=TCP, protocol_anomaly_score=0.35, protocol_violations=missing_tls, protocols=TCP, src_ip=192.168.1.185, src_port=49,433, start_time=1,779,139,826.6, tcp_flags=A, time_bucket=1,779,139,800, total_bytes=121, window_sec=30
tls_snitls_sni:copilot.microsoft.comsni=copilot.microsoft.com
tls_snitls_sni:browser.events.data.microsoft.comsni=browser.events.data.microsoft.com
tls_snitls_sni:chatgpt.comsni=chatgpt.com
KindIDNodes
flow_observed5-aryOBSe:fo:flow:4ac806f4d834flow:4ac806f4d834 β†’ host:192.168.1.185 β†’ host:20.62.59.32 β†’ port:tcp:443 β†’ svc:https
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-de97a19f0937505c:host:192.168.1.185SESSION-de97a19f0937505c β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-de97a19f0937505c:host:192.168.1.185SESSION-de97a19f0937505c β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:26faad66f81e:port:udp:44244flow:26faad66f81e β†’ port:udp:44244
FLOW_FROM_HOSTOBSe:from:SESSION-c4d9c40a7fec56be:host:192.168.1.185SESSION-c4d9c40a7fec56be β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:bf8f4a131249:port:udp:44244flow:bf8f4a131249 β†’ port:udp:44244
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-a019cb392bc23a7a:flow:65175f124256SESSION-a019cb392bc23a7a β†’ flow:65175f124256
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-055fd962754012c2:host:192.168.1.185SESSION-055fd962754012c2 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e66fd8e05921da5d:host:192.168.1.185SESSION-e66fd8e05921da5d β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-934baa2aae663ceb:host:151.101.113.140SESSION-934baa2aae663ceb β†’ host:151.101.113.140
FLOW_FROM_HOSTOBSe:from:SESSION-e86e0a049372cc85:host:192.168.1.185SESSION-e86e0a049372cc85 β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:7986b2093729:port:tcp:443flow:7986b2093729 β†’ port:tcp:443
flow_observed5-aryOBSe:fo:flow:c0b4f157e073flow:c0b4f157e073 β†’ host:192.168.1.185 β†’ host:34.111.31.13 β†’ port:tcp:443 β†’ svc:https
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-e86e0a049372cc85:host:192.168.1.185:host:142.250.113.95SESSION-e86e0a049372cc85 β†’ host:192.168.1.185 β†’ host:142.250.113.95
FLOW_TO_HOSTOBSe:to:SESSION-f8dc5b0051ee4914:host:192.168.1.1SESSION-f8dc5b0051ee4914 β†’ host:192.168.1.1
HOST_IN_ASNOBS 85%e:ha:host:192.73.244.245:asn:36236host:192.73.244.245 β†’ asn:36236
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-d146af26ba988e06:host:192.168.1.185SESSION-d146af26ba988e06 β†’ host:192.168.1.185
FLOW_TLS_SNIOBSe:fs:flow:189be888c3af:tls_sni:copilot.microsoft.comflow:189be888c3af β†’ tls_sni:copilot.microsoft.com
flow_observed4-aryOBSe:fo:flow:5b983251f483flow:5b983251f483 β†’ host:104.18.22.222 β†’ host:192.168.1.185 β†’ port:tcp:52133
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-9b68d4601d0ccd30:host:192.168.1.185:host:192.168.1.1SESSION-9b68d4601d0ccd30 β†’ host:192.168.1.185 β†’ host:192.168.1.1
FLOW_FROM_HOSTOBSe:from:SESSION-e565a4fbf5cff09b:host:192.168.1.185SESSION-e565a4fbf5cff09b β†’ host:192.168.1.185
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-e66fd8e05921da5d:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-e66fd8e05921da5d β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-b7338ba843b2dafa:flow:a3f08c1df1f5SESSION-b7338ba843b2dafa β†’ flow:a3f08c1df1f5
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-c4d9c40a7fec56be:host:135.234.174.40SESSION-c4d9c40a7fec56be β†’ host:135.234.174.40
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-9c85e6a530e7f20f:flow:9d482c927ad5SESSION-9c85e6a530e7f20f β†’ flow:9d482c927ad5
FLOW_FROM_HOSTOBSe:from:SESSION-2681df7af5f78270:host:97.178.32.239SESSION-2681df7af5f78270 β†’ host:97.178.32.239
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-055fd962754012c2:host:192.168.1.185:host:104.208.203.89SESSION-055fd962754012c2 β†’ host:192.168.1.185 β†’ host:104.208.203.89
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-934baa2aae663ceb:flow:eb3b47352f67SESSION-934baa2aae663ceb β†’ flow:eb3b47352f67
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-200a1edeb5081c1b:host:192.168.1.185SESSION-200a1edeb5081c1b β†’ host:192.168.1.185
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-423d6f8fa2a9f7bc:flow:df1c396b8733SESSION-423d6f8fa2a9f7bc β†’ flow:df1c396b8733
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-99947e3aab494326:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-99947e3aab494326 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-86bc6b9e53c222b0:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-86bc6b9e53c222b0 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
flow_observed5-aryOBSe:fo:flow:189be888c3afflow:189be888c3af β†’ host:192.168.1.185 β†’ host:104.18.23.222 β†’ port:tcp:443 β†’ svc:https
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-e881aa680da5dbf3:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-e881aa680da5dbf3 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
ASN_IN_ORGOBS 80%e:ao:asn:6167:org:Verizon Businessasn:6167 β†’ org:Verizon Business
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-9c85e6a530e7f20f:host:192.200.0.112SESSION-9c85e6a530e7f20f β†’ host:192.200.0.112
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-36cd4459caa078a9:host:135.234.174.40SESSION-36cd4459caa078a9 β†’ host:135.234.174.40
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-1065a64ded6cc44c:host:172.19.0.1SESSION-1065a64ded6cc44c β†’ host:172.19.0.1
flow_observed4-aryOBSe:fo:flow:a25fcb74f721flow:a25fcb74f721 β†’ host:216.24.57.7 β†’ host:192.168.1.185 β†’ port:tcp:58631
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-ce6603a48a5c4c37:host:192.168.1.185:host:23.219.160.5SESSION-ce6603a48a5c4c37 β†’ host:192.168.1.185 β†’ host:23.219.160.5
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-83d0b20751c23f69:host:192.168.1.1SESSION-83d0b20751c23f69 β†’ host:192.168.1.1
FLOW_TO_HOSTOBSe:to:SESSION-716de9787a03c45e:host:23.219.160.5SESSION-716de9787a03c45e β†’ host:23.219.160.5
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-2014bf32e6dab59e:host:192.168.1.185:host:151.101.113.140SESSION-2014bf32e6dab59e β†’ host:192.168.1.185 β†’ host:151.101.113.140
FLOW_FROM_HOSTOBSe:from:SESSION-17e440ba96a7a7b5:host:192.168.1.185SESSION-17e440ba96a7a7b5 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-716de9787a03c45e:host:192.168.1.185SESSION-716de9787a03c45e β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:6fe67514daf4:port:tcp:443flow:6fe67514daf4 β†’ port:tcp:443
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e881aa680da5dbf3:host:192.168.1.185SESSION-e881aa680da5dbf3 β†’ host:192.168.1.185
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-e86e0a049372cc85:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-e86e0a049372cc85 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
flow_observed5-aryOBSe:fo:flow:d83699920b5bflow:d83699920b5b β†’ host:192.168.1.185 β†’ host:151.101.113.140 β†’ port:tcp:443 β†’ svc:https
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-fa034e5132aecf5b:host:192.168.1.185SESSION-fa034e5132aecf5b β†’ host:192.168.1.185
HOST_IN_ASNOBS 85%e:ha:host:52.110.6.13:asn:8075host:52.110.6.13 β†’ asn:8075
HOST_IN_ASNOBS 85%e:ha:host:150.171.28.10:asn:8075host:150.171.28.10 β†’ asn:8075
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e25097cf84c7b988:host:192.168.1.185SESSION-e25097cf84c7b988 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-22420a928847cfad:host:192.168.1.185SESSION-22420a928847cfad β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-83d0b20751c23f69:host:192.168.1.185:host:192.168.1.1SESSION-83d0b20751c23f69 β†’ host:192.168.1.185 β†’ host:192.168.1.1
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-441bb1af5ec88ffb:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-441bb1af5ec88ffb β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_DST_PORTOBSe:fp:flow:21a678dc75de:port:tcp:443flow:21a678dc75de β†’ port:tcp:443
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-787a71cfd2c6f769:flow:c65476284ea0SESSION-787a71cfd2c6f769 β†’ flow:c65476284ea0
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-9dab8edd40d14d9d:SESSION-9dab8edd40d14d9dSESSION-9dab8edd40d14d9d β†’ pe:tls:SESSION-9dab8edd40d14d9d
HOST_GEO_ESTIMATEOBS 60%e:hg:host:192.73.243.135:geo_25.77010_-80.19280host:192.73.243.135 β†’ geo_25.77010_-80.19280
FLOW_DST_PORTOBSe:fp:flow:c65476284ea0:port:tcp:61509flow:c65476284ea0 β†’ port:tcp:61509
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-10cf97843d85c279:host:209.177.156.94SESSION-10cf97843d85c279 β†’ host:209.177.156.94
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-81e5b5be161de125:host:192.168.1.185SESSION-81e5b5be161de125 β†’ host:192.168.1.185
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-e881aa680da5dbf3:flow:f3b81336df74SESSION-e881aa680da5dbf3 β†’ flow:f3b81336df74
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-58f9cafe500f64ad:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-58f9cafe500f64ad β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_FROM_HOSTOBSe:from:SESSION-423d6f8fa2a9f7bc:host:23.213.232.172SESSION-423d6f8fa2a9f7bc β†’ host:23.213.232.172
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-502ccca87ddbbb24:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-502ccca87ddbbb24 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-7bf53771cd98ec17:host:192.168.1.1SESSION-7bf53771cd98ec17 β†’ host:192.168.1.1
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-d146af26ba988e06:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-d146af26ba988e06 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-e565a4fbf5cff09b:flow:6fe67514daf4SESSION-e565a4fbf5cff09b β†’ flow:6fe67514daf4
FLOW_FROM_HOSTOBSe:from:SESSION-7bf53771cd98ec17:host:192.168.1.185SESSION-7bf53771cd98ec17 β†’ host:192.168.1.185
HOST_IN_ASNOBS 85%e:ha:host:199.165.136.100:asn:14618host:199.165.136.100 β†’ asn:14618
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-dabcbf693ac9fbef:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-dabcbf693ac9fbef β†’ BSG-HORIZ_SCAN-cd2c52661c4b
FLOW_DST_PORTOBSe:fp:flow:4ac806f4d834:port:tcp:443flow:4ac806f4d834 β†’ port:tcp:443
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-2681df7af5f78270:host:192.168.1.185SESSION-2681df7af5f78270 β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:c0b4f157e073:port:tcp:443flow:c0b4f157e073 β†’ port:tcp:443
flow_observed4-aryOBSe:fo:flow:df1c396b8733flow:df1c396b8733 β†’ host:23.213.232.172 β†’ host:192.168.1.185 β†’ port:tcp:51966
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-200a1edeb5081c1b:host:52.110.6.13:host:192.168.1.185SESSION-200a1edeb5081c1b β†’ host:52.110.6.13 β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:ab2fda60ec38:port:tcp:443flow:ab2fda60ec38 β†’ port:tcp:443
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-200a1edeb5081c1b:host:52.110.6.13SESSION-200a1edeb5081c1b β†’ host:52.110.6.13
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-b7338ba843b2dafa:host:192.168.1.185:host:192.73.248.83SESSION-b7338ba843b2dafa β†’ host:192.168.1.185 β†’ host:192.73.248.83
FLOW_FROM_HOSTOBSe:from:SESSION-c8f5f362e7c0c5c8:host:216.24.57.251SESSION-c8f5f362e7c0c5c8 β†’ host:216.24.57.251
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-200a1edeb5081c1b:SESSION-200a1edeb5081c1bSESSION-200a1edeb5081c1b β†’ pe:tls:SESSION-200a1edeb5081c1b
ASN_IN_ORGOBS 80%e:ao:asn:24940:org:Hetzner Online GmbHasn:24940 β†’ org:Hetzner Online GmbH
FLOW_DST_PORTOBSe:fp:flow:e34282443dab:port:udp:443flow:e34282443dab β†’ port:udp:443
flow_observed4-aryOBSe:fo:flow:60dd2a974649flow:60dd2a974649 β†’ host:192.168.1.185 β†’ host:192.168.1.1 β†’ port:udp:5351
SESSION_CONTAINS_EVENTOBSe:pe:pe:dns:SESSION-08bfd8721a383a39:SESSION-08bfd8721a383a39SESSION-08bfd8721a383a39 β†’ pe:dns:SESSION-08bfd8721a383a39
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-9dab8edd40d14d9d:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-9dab8edd40d14d9d β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_DST_PORTOBSe:fp:flow:c44b4fd56f98:port:udp:60920flow:c44b4fd56f98 β†’ port:udp:60920
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-9b68d4601d0ccd30:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-9b68d4601d0ccd30 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-b7338ba843b2dafa:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-b7338ba843b2dafa β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-e0cdf80170e46e9e:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-e0cdf80170e46e9e β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e6729d0ebc579395:host:97.178.32.239SESSION-e6729d0ebc579395 β†’ host:97.178.32.239
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-f8dc5b0051ee4914:flow:bf7a9427297dSESSION-f8dc5b0051ee4914 β†’ flow:bf7a9427297d
FLOW_TO_HOSTOBSe:to:SESSION-741380b5a9a3a6c7:host:192.168.1.185SESSION-741380b5a9a3a6c7 β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-1065a64ded6cc44c:host:192.168.1.185:host:172.19.0.1SESSION-1065a64ded6cc44c β†’ host:192.168.1.185 β†’ host:172.19.0.1
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-423d6f8fa2a9f7bc:host:23.213.232.172:host:192.168.1.185SESSION-423d6f8fa2a9f7bc β†’ host:23.213.232.172 β†’ host:192.168.1.185
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-348feef1c6ca6285:SESSION-348feef1c6ca6285SESSION-348feef1c6ca6285 β†’ pe:tls:SESSION-348feef1c6ca6285
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-22420a928847cfad:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-22420a928847cfad β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-fa034e5132aecf5b:flow:abe950115ba3SESSION-fa034e5132aecf5b β†’ flow:abe950115ba3
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-83d0b20751c23f69:flow:4eed5ff51111SESSION-83d0b20751c23f69 β†’ flow:4eed5ff51111
FLOW_DST_PORTOBSe:fp:flow:4f5810e72704:port:udp:3478flow:4f5810e72704 β†’ port:udp:3478
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-9b68d4601d0ccd30:host:192.168.1.185SESSION-9b68d4601d0ccd30 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-2014bf32e6dab59e:host:192.168.1.185SESSION-2014bf32e6dab59e β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-dabcbf693ac9fbef:host:192.168.1.185SESSION-dabcbf693ac9fbef β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-68666b77cce29d40:host:192.168.1.185SESSION-68666b77cce29d40 β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:62d01d1bf747:port:udp:3478flow:62d01d1bf747 β†’ port:udp:3478
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-1ea83345da6e2df0:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-1ea83345da6e2df0 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
HOST_GEO_ESTIMATEOBS 60%e:hg:host:216.24.57.251:geo_37.75100_-97.82200host:216.24.57.251 β†’ geo_37.75100_-97.82200
FLOW_FROM_HOSTOBSe:from:SESSION-65a9e51617aa2712:host:192.168.1.185SESSION-65a9e51617aa2712 β†’ host:192.168.1.185
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-05305b96b26cdffd:flow:0380e0cd29dcSESSION-05305b96b26cdffd β†’ flow:0380e0cd29dc
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-e5c653feb7de823f:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-e5c653feb7de823f β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_DST_PORTOBSe:fp:flow:660ca437efa1:port:udp:53flow:660ca437efa1 β†’ port:udp:53
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 90%e:bsg:SESSION-21bfec774060aafb:BSG-BEACON-4bc57cbec7cdSESSION-21bfec774060aafb β†’ BSG-BEACON-4bc57cbec7cd
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-10cf97843d85c279:host:192.168.1.185SESSION-10cf97843d85c279 β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-441bb1af5ec88ffb:host:192.168.1.185:host:76.76.21.22SESSION-441bb1af5ec88ffb β†’ host:192.168.1.185 β†’ host:76.76.21.22
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-58f9cafe500f64ad:flow:660ca437efa1SESSION-58f9cafe500f64ad β†’ flow:660ca437efa1
FLOW_DST_PORTOBSe:fp:flow:cb933110cf94:port:tcp:443flow:cb933110cf94 β†’ port:tcp:443
FLOW_FROM_HOSTOBSe:from:SESSION-200a1edeb5081c1b:host:52.110.6.13SESSION-200a1edeb5081c1b β†’ host:52.110.6.13
flow_observed4-aryOBSe:fo:flow:7fc08133133dflow:7fc08133133d β†’ host:192.168.1.185 β†’ host:172.19.0.1 β†’ port:udp:44244
PORT_IMPLIED_SERVICEIMP 70%e:ps:port:tcp:443:svc:httpsport:tcp:443 β†’ svc:https
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-f8dc5b0051ee4914:host:192.168.1.185:host:192.168.1.1SESSION-f8dc5b0051ee4914 β†’ host:192.168.1.185 β†’ host:192.168.1.1
FLOW_FROM_HOSTOBSe:from:SESSION-329be171c0b80b92:host:192.168.1.185SESSION-329be171c0b80b92 β†’ host:192.168.1.185
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-4cf06bd9f9c07bb4:flow:478de54cd94aSESSION-4cf06bd9f9c07bb4 β†’ flow:478de54cd94a
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-e6ad21d692182871:SESSION-e6ad21d692182871SESSION-e6ad21d692182871 β†’ pe:tls:SESSION-e6ad21d692182871
FLOW_FROM_HOSTOBSe:from:SESSION-3cb87513d2c7904f:host:192.168.1.185SESSION-3cb87513d2c7904f β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-787a71cfd2c6f769:host:192.168.1.185SESSION-787a71cfd2c6f769 β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-e565a4fbf5cff09b:host:192.168.1.185:host:192.73.248.83SESSION-e565a4fbf5cff09b β†’ host:192.168.1.185 β†’ host:192.73.248.83
FLOW_TO_HOSTOBSe:to:SESSION-e66fd8e05921da5d:host:172.18.0.1SESSION-e66fd8e05921da5d β†’ host:172.18.0.1
flow_observed5-aryOBSe:fo:flow:7986b2093729flow:7986b2093729 β†’ host:192.168.1.185 β†’ host:104.18.32.47 β†’ port:tcp:443 β†’ svc:https
FLOW_DST_PORTOBSe:fp:flow:60dd2a974649:port:udp:5351flow:60dd2a974649 β†’ port:udp:5351
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-06fade4febc8462c:SESSION-06fade4febc8462cSESSION-06fade4febc8462c β†’ pe:tls:SESSION-06fade4febc8462c
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-b7d90a2138968fa3:SESSION-b7d90a2138968fa3SESSION-b7d90a2138968fa3 β†’ pe:tls:SESSION-b7d90a2138968fa3
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-4cf06bd9f9c07bb4:host:192.168.1.185:host:97.178.32.239SESSION-4cf06bd9f9c07bb4 β†’ host:192.168.1.185 β†’ host:97.178.32.239
FLOW_FROM_HOSTOBSe:from:SESSION-99947e3aab494326:host:192.200.0.112SESSION-99947e3aab494326 β†’ host:192.200.0.112
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-cbcc97483386b4f3:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-cbcc97483386b4f3 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-934baa2aae663ceb:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-934baa2aae663ceb β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-5419af02605f5da4:host:97.178.32.239SESSION-5419af02605f5da4 β†’ host:97.178.32.239
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-502ccca87ddbbb24:host:192.168.1.185SESSION-502ccca87ddbbb24 β†’ host:192.168.1.185
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-502ccca87ddbbb24:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-502ccca87ddbbb24 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-d7f6ed06cf3ab18b:host:97.178.32.239:host:192.168.1.185SESSION-d7f6ed06cf3ab18b β†’ host:97.178.32.239 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-9dab8edd40d14d9d:host:192.168.1.185SESSION-9dab8edd40d14d9d β†’ host:192.168.1.185
flow_observed5-aryOBSe:fo:flow:9aa8161296f7flow:9aa8161296f7 β†’ host:192.168.1.185 β†’ host:199.165.136.100 β†’ port:tcp:443 β†’ svc:https
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-0e59fb5fe4c720df:host:192.168.1.185SESSION-0e59fb5fe4c720df β†’ host:192.168.1.185
HOST_GEO_ESTIMATEOBS 60%e:hg:host:23.213.232.172:geo_32.77970_-96.80220host:23.213.232.172 β†’ geo_32.77970_-96.80220
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-bcd07bc8e00bd126:host:209.177.158.246SESSION-bcd07bc8e00bd126 β†’ host:209.177.158.246
flow_observed4-aryOBSe:fo:flow:478de54cd94aflow:478de54cd94a β†’ host:192.168.1.185 β†’ host:97.178.32.239 β†’ port:udp:31036
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-9dab8edd40d14d9d:host:104.18.39.21:host:192.168.1.185SESSION-9dab8edd40d14d9d β†’ host:104.18.39.21 β†’ host:192.168.1.185
HOST_GEO_ESTIMATEOBS 60%e:hg:host:23.219.160.5:geo_29.75390_-95.35900host:23.219.160.5 β†’ geo_29.75390_-95.35900
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-c8f5f362e7c0c5c8:host:192.168.1.185SESSION-c8f5f362e7c0c5c8 β†’ host:192.168.1.185
flow_observed5-aryOBSe:fo:flow:eb3b47352f67flow:eb3b47352f67 β†’ host:192.168.1.185 β†’ host:151.101.113.140 β†’ port:tcp:443 β†’ svc:https
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-502ccca87ddbbb24:flow:1cae684ccaf1SESSION-502ccca87ddbbb24 β†’ flow:1cae684ccaf1
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-e53f703ab7b48a77:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-e53f703ab7b48a77 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-fa034e5132aecf5b:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-fa034e5132aecf5b β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_TO_HOSTOBSe:to:SESSION-bcd07bc8e00bd126:host:209.177.158.246SESSION-bcd07bc8e00bd126 β†’ host:209.177.158.246
FLOW_FROM_HOSTOBSe:from:SESSION-787a71cfd2c6f769:host:162.159.128.61SESSION-787a71cfd2c6f769 β†’ host:162.159.128.61
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-e565a4fbf5cff09b:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-e565a4fbf5cff09b β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-1065a64ded6cc44c:host:192.168.1.185SESSION-1065a64ded6cc44c β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-21bfec774060aafb:host:192.168.1.185:host:192.168.1.1SESSION-21bfec774060aafb β†’ host:192.168.1.185 β†’ host:192.168.1.1
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-b7338ba843b2dafa:host:192.73.248.83SESSION-b7338ba843b2dafa β†’ host:192.73.248.83
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-e6ad21d692182871:host:192.168.1.185:host:199.165.136.100SESSION-e6ad21d692182871 β†’ host:192.168.1.185 β†’ host:199.165.136.100
HOST_IN_ASNOBS 85%e:ha:host:192.200.0.112:asn:16509host:192.200.0.112 β†’ asn:16509
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-502ccca87ddbbb24:host:35.190.80.1SESSION-502ccca87ddbbb24 β†’ host:35.190.80.1
FLOW_FROM_HOSTOBSe:from:SESSION-e881aa680da5dbf3:host:192.168.1.185SESSION-e881aa680da5dbf3 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-cbcc97483386b4f3:host:192.168.1.185SESSION-cbcc97483386b4f3 β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-184b3698d564c9c7:host:192.168.1.185SESSION-184b3698d564c9c7 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-bc4350b5c6d66f3f:host:192.168.1.185SESSION-bc4350b5c6d66f3f β†’ host:192.168.1.185
HOST_GEO_ESTIMATEOBS 60%e:hg:host:216.239.32.223:geo_37.75100_-97.82200host:216.239.32.223 β†’ geo_37.75100_-97.82200
FLOW_FROM_HOSTOBSe:from:SESSION-a019cb392bc23a7a:host:192.168.1.185SESSION-a019cb392bc23a7a β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-787a71cfd2c6f769:host:162.159.128.61SESSION-787a71cfd2c6f769 β†’ host:162.159.128.61
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-86bc6b9e53c222b0:host:23.219.160.5SESSION-86bc6b9e53c222b0 β†’ host:23.219.160.5
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-a019cb392bc23a7a:SESSION-a019cb392bc23a7aSESSION-a019cb392bc23a7a β†’ pe:tls:SESSION-a019cb392bc23a7a
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-b7d90a2138968fa3:flow:495f7c8d94fdSESSION-b7d90a2138968fa3 β†’ flow:495f7c8d94fd
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e565a4fbf5cff09b:host:192.73.248.83SESSION-e565a4fbf5cff09b β†’ host:192.73.248.83
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e881aa680da5dbf3:host:151.101.112.217SESSION-e881aa680da5dbf3 β†’ host:151.101.112.217
FLOW_DST_PORTOBSe:fp:flow:eb3b47352f67:port:tcp:443flow:eb3b47352f67 β†’ port:tcp:443
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-7b2b00e0ceb88c09:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-7b2b00e0ceb88c09 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-e6ad21d692182871:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-e6ad21d692182871 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-10cf97843d85c279:flow:fdf049da8b14SESSION-10cf97843d85c279 β†’ flow:fdf049da8b14
FLOW_DST_PORTOBSe:fp:flow:a25fcb74f721:port:tcp:58631flow:a25fcb74f721 β†’ port:tcp:58631
FLOW_DST_PORTOBSe:fp:flow:df1c396b8733:port:tcp:51966flow:df1c396b8733 β†’ port:tcp:51966
FLOW_TO_HOSTOBSe:to:SESSION-7b2b00e0ceb88c09:host:20.62.59.32SESSION-7b2b00e0ceb88c09 β†’ host:20.62.59.32
FLOW_FROM_HOSTOBSe:from:SESSION-dabcbf693ac9fbef:host:192.168.1.185SESSION-dabcbf693ac9fbef β†’ host:192.168.1.185
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-1f115942b61afe54:flow:4f5810e72704SESSION-1f115942b61afe54 β†’ flow:4f5810e72704
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-8c7ddbb6fe26a9a9:flow:c44b4fd56f98SESSION-8c7ddbb6fe26a9a9 β†’ flow:c44b4fd56f98
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-9c85e6a530e7f20f:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-9c85e6a530e7f20f β†’ BSG-HORIZ_SCAN-cd2c52661c4b
FLOW_TO_HOSTOBSe:to:SESSION-8fd6ad39adf47a18:host:192.168.1.185SESSION-8fd6ad39adf47a18 β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:5a246bdf60e4:port:tcp:443flow:5a246bdf60e4 β†’ port:tcp:443
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-0e59fb5fe4c720df:host:209.177.156.94SESSION-0e59fb5fe4c720df β†’ host:209.177.156.94
flow_observed4-aryOBSe:fo:flow:65c7de267840flow:65c7de267840 β†’ host:192.168.1.185 β†’ host:192.168.1.1 β†’ port:udp:5351
HOST_IN_ASNOBS 85%e:ha:host:216.24.57.7:asn:397273host:216.24.57.7 β†’ asn:397273
FLOW_QUERIED_DNSOBSe:fd:flow:660ca437efa1:dns:signaler-pa.clients6.google.comflow:660ca437efa1 β†’ dns:signaler-pa.clients6.google.com
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e6729d0ebc579395:host:192.168.1.185SESSION-e6729d0ebc579395 β†’ host:192.168.1.185
HOST_IN_ASNOBS 85%e:ha:host:209.177.158.246:asn:36236host:209.177.158.246 β†’ asn:36236
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-3cb87513d2c7904f:host:192.168.1.185:host:192.168.1.1SESSION-3cb87513d2c7904f β†’ host:192.168.1.185 β†’ host:192.168.1.1
flow_observed5-aryOBSe:fo:flow:9d482c927ad5flow:9d482c927ad5 β†’ host:192.168.1.185 β†’ host:192.200.0.112 β†’ port:tcp:443 β†’ svc:https
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-c4d9c40a7fec56be:host:192.168.1.185SESSION-c4d9c40a7fec56be β†’ host:192.168.1.185
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-1f115942b61afe54:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-1f115942b61afe54 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
HOST_GEO_ESTIMATEOBS 60%e:hg:host:209.177.156.94:geo_32.77970_-96.80220host:209.177.156.94 β†’ geo_32.77970_-96.80220
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-2681df7af5f78270:flow:7395be855a32SESSION-2681df7af5f78270 β†’ flow:7395be855a32
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-a019cb392bc23a7a:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-a019cb392bc23a7a β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_DST_PORTOBSe:fp:flow:f79c1639a1f7:port:udp:11130flow:f79c1639a1f7 β†’ port:udp:11130
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-e25097cf84c7b988:host:192.168.1.185:host:97.178.32.239SESSION-e25097cf84c7b988 β†’ host:192.168.1.185 β†’ host:97.178.32.239
FLOW_TLS_SNIOBSe:fs:flow:7986b2093729:tls_sni:chatgpt.comflow:7986b2093729 β†’ tls_sni:chatgpt.com
flow_observed5-aryOBSe:fo:flow:46c89f86a16aflow:46c89f86a16a β†’ host:192.168.1.185 β†’ host:23.219.160.5 β†’ port:udp:443 β†’ svc:https
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-4cf06bd9f9c07bb4:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-4cf06bd9f9c07bb4 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-de97a19f0937505c:host:104.18.1.62SESSION-de97a19f0937505c β†’ host:104.18.1.62
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-81e5b5be161de125:host:192.168.1.185:host:151.101.114.172SESSION-81e5b5be161de125 β†’ host:192.168.1.185 β†’ host:151.101.114.172
flow_observed4-aryOBSe:fo:flow:1fbee9feb06dflow:1fbee9feb06d β†’ host:104.18.1.62 β†’ host:192.168.1.185 β†’ port:tcp:51146
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-9c845bfb2b534b59:flow:c378386f9a22SESSION-9c845bfb2b534b59 β†’ flow:c378386f9a22
FLOW_TO_HOSTOBSe:to:SESSION-0e59fb5fe4c720df:host:192.168.1.185SESSION-0e59fb5fe4c720df β†’ host:192.168.1.185
flow_observed3-aryOBSe:fo:flow:d658b18ff560flow:d658b18ff560 β†’ host:192.168.1.165 β†’ host:224.0.0.22
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-934baa2aae663ceb:host:192.168.1.185:host:151.101.113.140SESSION-934baa2aae663ceb β†’ host:192.168.1.185 β†’ host:151.101.113.140
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-5673cdc8e15ecc28:flow:9cc54a60d88aSESSION-5673cdc8e15ecc28 β†’ flow:9cc54a60d88a
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-5419af02605f5da4:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-5419af02605f5da4 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-8c7ddbb6fe26a9a9:host:192.168.1.185SESSION-8c7ddbb6fe26a9a9 β†’ host:192.168.1.185
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-8394aca80c2a0790:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-8394aca80c2a0790 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-055fd962754012c2:flow:779733f74cebSESSION-055fd962754012c2 β†’ flow:779733f74ceb
FLOW_TO_HOSTOBSe:to:SESSION-7bf53771cd98ec17:host:192.168.1.1SESSION-7bf53771cd98ec17 β†’ host:192.168.1.1
HOST_IN_ASNOBS 85%e:ha:host:209.177.156.94:asn:36236host:209.177.156.94 β†’ asn:36236
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-184b3698d564c9c7:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-184b3698d564c9c7 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
HOST_GEO_ESTIMATEOBS 60%e:hg:host:76.76.21.22:geo_34.02330_-117.85120host:76.76.21.22 β†’ geo_34.02330_-117.85120
FLOW_TO_HOSTOBSe:to:SESSION-e5c653feb7de823f:host:192.73.243.135SESSION-e5c653feb7de823f β†’ host:192.73.243.135
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e25097cf84c7b988:host:97.178.32.239SESSION-e25097cf84c7b988 β†’ host:97.178.32.239
FLOW_FROM_HOSTOBSe:from:SESSION-08bfd8721a383a39:host:192.168.1.185SESSION-08bfd8721a383a39 β†’ host:192.168.1.185
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-83d0b20751c23f69:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-83d0b20751c23f69 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-329be171c0b80b92:flow:a912cd07306bSESSION-329be171c0b80b92 β†’ flow:a912cd07306b
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-8394aca80c2a0790:SESSION-8394aca80c2a0790SESSION-8394aca80c2a0790 β†’ pe:tls:SESSION-8394aca80c2a0790
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-2014bf32e6dab59e:flow:d83699920b5bSESSION-2014bf32e6dab59e β†’ flow:d83699920b5b
flow_observed4-aryOBSe:fo:flow:dd3dd13e1b60flow:dd3dd13e1b60 β†’ host:192.168.1.185 β†’ host:209.177.158.246 β†’ port:udp:3478
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-e6729d0ebc579395:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-e6729d0ebc579395 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
HOST_IN_ASNOBS 85%e:ha:host:13.107.226.57:asn:8075host:13.107.226.57 β†’ asn:8075
ASN_IN_ORGOBS 80%e:ao:asn:36236:org:NetActuate, Incasn:36236 β†’ org:NetActuate, Inc
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-8fd6ad39adf47a18:SESSION-8fd6ad39adf47a18SESSION-8fd6ad39adf47a18 β†’ pe:tls:SESSION-8fd6ad39adf47a18
FLOW_TO_HOSTOBSe:to:SESSION-5673cdc8e15ecc28:host:192.168.1.185SESSION-5673cdc8e15ecc28 β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-8fd6ad39adf47a18:host:104.18.36.216:host:192.168.1.185SESSION-8fd6ad39adf47a18 β†’ host:104.18.36.216 β†’ host:192.168.1.185
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-8394aca80c2a0790:flow:7be9da9aa76dSESSION-8394aca80c2a0790 β†’ flow:7be9da9aa76d
HOST_IN_ASNOBS 85%e:ha:host:192.73.248.83:asn:36236host:192.73.248.83 β†’ asn:36236
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-86bc6b9e53c222b0:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-86bc6b9e53c222b0 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 95%e:bsg:SESSION-d146af26ba988e06:BSG-DATA_EXFIL-78b438a917b5SESSION-d146af26ba988e06 β†’ BSG-DATA_EXFIL-78b438a917b5
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-3cb87513d2c7904f:flow:60dd2a974649SESSION-3cb87513d2c7904f β†’ flow:60dd2a974649
FLOW_QUERIED_DNSOBSe:fd:flow:dc8e0c394478:dns:bat.bing.comflow:dc8e0c394478 β†’ dns:bat.bing.com
SESSION_CONTAINS_EVENTOBSe:pe:pe:syn:SESSION-8394aca80c2a0790:SESSION-8394aca80c2a0790SESSION-8394aca80c2a0790 β†’ pe:syn:SESSION-8394aca80c2a0790
SESSION_CONTAINS_EVENTOBSe:pe:pe:syn:SESSION-21bfec774060aafb:SESSION-21bfec774060aafbSESSION-21bfec774060aafb β†’ pe:syn:SESSION-21bfec774060aafb
flow_observed4-aryOBSe:fo:flow:f79c1639a1f7flow:f79c1639a1f7 β†’ host:192.168.1.185 β†’ host:97.178.32.239 β†’ port:udp:11130
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-65a9e51617aa2712:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-65a9e51617aa2712 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 90%e:bsg:SESSION-2014bf32e6dab59e:BSG-BEACON-3fa1dca5627cSESSION-2014bf32e6dab59e β†’ BSG-BEACON-3fa1dca5627c
FLOW_TO_HOSTOBSe:to:SESSION-9b68d4601d0ccd30:host:192.168.1.1SESSION-9b68d4601d0ccd30 β†’ host:192.168.1.1
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-604f49b2ccac8492:flow:03d3562fa35fSESSION-604f49b2ccac8492 β†’ flow:03d3562fa35f
HOST_GEO_ESTIMATEOBS 60%e:hg:host:142.250.113.95:geo_37.75100_-97.82200host:142.250.113.95 β†’ geo_37.75100_-97.82200
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-e565a4fbf5cff09b:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-e565a4fbf5cff09b β†’ BSG-HORIZ_SCAN-cd2c52661c4b
FLOW_FROM_HOSTOBSe:from:SESSION-e0cdf80170e46e9e:host:192.168.1.185SESSION-e0cdf80170e46e9e β†’ host:192.168.1.185
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-ea1d23994577309a:flow:5b983251f483SESSION-ea1d23994577309a β†’ flow:5b983251f483
flow_observed5-aryOBSe:fo:flow:c378386f9a22flow:c378386f9a22 β†’ host:192.168.1.185 β†’ host:150.171.28.10 β†’ port:tcp:443 β†’ svc:https
flow_observed5-aryOBSe:fo:flow:e34282443dabflow:e34282443dab β†’ host:192.168.1.185 β†’ host:142.250.115.95 β†’ port:udp:443 β†’ svc:https
FLOW_TO_HOSTOBSe:to:SESSION-08bfd8721a383a39:host:192.168.1.1SESSION-08bfd8721a383a39 β†’ host:192.168.1.1
FLOW_TO_HOSTOBSe:to:SESSION-423d6f8fa2a9f7bc:host:192.168.1.185SESSION-423d6f8fa2a9f7bc β†’ host:192.168.1.185
flow_observed4-aryOBSe:fo:flow:ef26bc2c964dflow:ef26bc2c964d β†’ host:172.64.151.22 β†’ host:192.168.1.185 β†’ port:tcp:62104
FLOW_TO_HOSTOBSe:to:SESSION-441bb1af5ec88ffb:host:76.76.21.22SESSION-441bb1af5ec88ffb β†’ host:76.76.21.22
FLOW_DST_PORTOBSe:fp:flow:9cc54a60d88a:port:tcp:54986flow:9cc54a60d88a β†’ port:tcp:54986
flow_observed5-aryOBSe:fo:flow:5a246bdf60e4flow:5a246bdf60e4 β†’ host:192.168.1.185 β†’ host:135.234.174.40 β†’ port:tcp:443 β†’ svc:https
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-86bc6b9e53c222b0:flow:46c89f86a16aSESSION-86bc6b9e53c222b0 β†’ flow:46c89f86a16a
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-b7d90a2138968fa3:host:209.177.156.94:host:192.168.1.185SESSION-b7d90a2138968fa3 β†’ host:209.177.156.94 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-bcd07bc8e00bd126:host:192.168.1.185SESSION-bcd07bc8e00bd126 β†’ host:192.168.1.185
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-7b2b00e0ceb88c09:SESSION-7b2b00e0ceb88c09SESSION-7b2b00e0ceb88c09 β†’ pe:tls:SESSION-7b2b00e0ceb88c09
flow_observed4-aryOBSe:fo:flow:a912cd07306bflow:a912cd07306b β†’ host:192.168.1.185 β†’ host:172.29.16.1 β†’ port:udp:41641
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-2014bf32e6dab59e:host:151.101.113.140SESSION-2014bf32e6dab59e β†’ host:151.101.113.140
HOST_GEO_ESTIMATEOBS 60%e:hg:host:34.111.31.13:geo_39.10270_-94.57780host:34.111.31.13 β†’ geo_39.10270_-94.57780
FLOW_FROM_HOSTOBSe:from:SESSION-5673cdc8e15ecc28:host:167.235.217.196SESSION-5673cdc8e15ecc28 β†’ host:167.235.217.196
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-06fade4febc8462c:host:192.168.1.185:host:104.18.23.222SESSION-06fade4febc8462c β†’ host:192.168.1.185 β†’ host:104.18.23.222
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e565a4fbf5cff09b:host:192.168.1.185SESSION-e565a4fbf5cff09b β†’ host:192.168.1.185
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-bc4350b5c6d66f3f:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-bc4350b5c6d66f3f β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-9c845bfb2b534b59:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-9c845bfb2b534b59 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
HOST_GEO_ESTIMATEOBS 60%e:hg:host:199.165.136.100:geo_43.63190_-79.37160host:199.165.136.100 β†’ geo_43.63190_-79.37160
FLOW_DST_PORTOBSe:fp:flow:dc8e0c394478:port:udp:53flow:dc8e0c394478 β†’ port:udp:53
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e66fd8e05921da5d:host:172.18.0.1SESSION-e66fd8e05921da5d β†’ host:172.18.0.1
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-7b2b00e0ceb88c09:host:192.168.1.185SESSION-7b2b00e0ceb88c09 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-99947e3aab494326:host:192.168.1.185SESSION-99947e3aab494326 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-05305b96b26cdffd:host:104.18.39.21SESSION-05305b96b26cdffd β†’ host:104.18.39.21
flow_observed4-aryOBSe:fo:flow:a42e7b1c53d5flow:a42e7b1c53d5 β†’ host:192.168.1.185 β†’ host:209.177.156.94 β†’ port:udp:3478
FLOW_TO_HOSTOBSe:to:SESSION-ea1d23994577309a:host:192.168.1.185SESSION-ea1d23994577309a β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-423d6f8fa2a9f7bc:host:192.168.1.185SESSION-423d6f8fa2a9f7bc β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-dabcbf693ac9fbef:host:150.171.28.10SESSION-dabcbf693ac9fbef β†’ host:150.171.28.10
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-bc4350b5c6d66f3f:SESSION-bc4350b5c6d66f3fSESSION-bc4350b5c6d66f3f β†’ pe:tls:SESSION-bc4350b5c6d66f3f
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-e53f703ab7b48a77:SESSION-e53f703ab7b48a77SESSION-e53f703ab7b48a77 β†’ pe:tls:SESSION-e53f703ab7b48a77
FLOW_QUERIED_DNSOBSe:fd:flow:0c699e4ab5c4:dns:ctldl.windowsupdate.comflow:0c699e4ab5c4 β†’ dns:ctldl.windowsupdate.com
FLOW_FROM_HOSTOBSe:from:SESSION-83d0b20751c23f69:host:192.168.1.185SESSION-83d0b20751c23f69 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-ce6603a48a5c4c37:host:192.168.1.185SESSION-ce6603a48a5c4c37 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-58f9cafe500f64ad:host:192.168.1.185SESSION-58f9cafe500f64ad β†’ host:192.168.1.185
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-e6729d0ebc579395:flow:137f07aaadb4SESSION-e6729d0ebc579395 β†’ flow:137f07aaadb4
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-787a71cfd2c6f769:host:192.168.1.185SESSION-787a71cfd2c6f769 β†’ host:192.168.1.185
HOST_IN_ASNOBS 85%e:ha:host:20.62.59.32:asn:8075host:20.62.59.32 β†’ asn:8075
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-17e440ba96a7a7b5:host:192.168.1.185:host:142.250.115.95SESSION-17e440ba96a7a7b5 β†’ host:192.168.1.185 β†’ host:142.250.115.95
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-86bc6b9e53c222b0:host:192.168.1.185SESSION-86bc6b9e53c222b0 β†’ host:192.168.1.185
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-a019cb392bc23a7a:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-a019cb392bc23a7a β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-200a1edeb5081c1b:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-200a1edeb5081c1b β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-604f49b2ccac8492:host:97.178.32.239SESSION-604f49b2ccac8492 β†’ host:97.178.32.239
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-9c85e6a530e7f20f:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-9c85e6a530e7f20f β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_FROM_HOSTOBSe:from:SESSION-858ec5d25a7b6232:host:192.168.1.185SESSION-858ec5d25a7b6232 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-10cf97843d85c279:host:192.168.1.185SESSION-10cf97843d85c279 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-f8dc5b0051ee4914:host:192.168.1.185SESSION-f8dc5b0051ee4914 β†’ host:192.168.1.185
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-348feef1c6ca6285:flow:300bb0be41cfSESSION-348feef1c6ca6285 β†’ flow:300bb0be41cf
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-e53f703ab7b48a77:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-e53f703ab7b48a77 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_FROM_HOSTOBSe:from:SESSION-de97a19f0937505c:host:104.18.1.62SESSION-de97a19f0937505c β†’ host:104.18.1.62
FLOW_TO_HOSTOBSe:to:SESSION-83d0b20751c23f69:host:192.168.1.1SESSION-83d0b20751c23f69 β†’ host:192.168.1.1
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-9c845bfb2b534b59:host:150.171.28.10SESSION-9c845bfb2b534b59 β†’ host:150.171.28.10
FLOW_DST_PORTOBSe:fp:flow:c378386f9a22:port:tcp:443flow:c378386f9a22 β†’ port:tcp:443
FLOW_DST_PORTOBSe:fp:flow:919c57e90236:port:udp:443flow:919c57e90236 β†’ port:udp:443
FLOW_FROM_HOSTOBSe:from:SESSION-1ea83345da6e2df0:host:192.168.1.165SESSION-1ea83345da6e2df0 β†’ host:192.168.1.165
FLOW_DST_PORTOBSe:fp:flow:f6fc82e11042:port:udp:5351flow:f6fc82e11042 β†’ port:udp:5351
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-348feef1c6ca6285:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-348feef1c6ca6285 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-9b68d4601d0ccd30:host:192.168.1.1SESSION-9b68d4601d0ccd30 β†’ host:192.168.1.1
flow_observed5-aryOBSe:fo:flow:660ca437efa1flow:660ca437efa1 β†’ host:192.168.1.185 β†’ host:192.168.1.1 β†’ port:udp:53 β†’ svc:dns
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-58f9cafe500f64ad:host:192.168.1.1SESSION-58f9cafe500f64ad β†’ host:192.168.1.1
FLOW_FROM_HOSTOBSe:from:SESSION-184b3698d564c9c7:host:216.24.57.7SESSION-184b3698d564c9c7 β†’ host:216.24.57.7
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-e881aa680da5dbf3:SESSION-e881aa680da5dbf3SESSION-e881aa680da5dbf3 β†’ pe:tls:SESSION-e881aa680da5dbf3
FLOW_DST_PORTOBSe:fp:flow:f19ee6508782:port:tcp:58457flow:f19ee6508782 β†’ port:tcp:58457
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-858ec5d25a7b6232:flow:f79c1639a1f7SESSION-858ec5d25a7b6232 β†’ flow:f79c1639a1f7
PORT_IMPLIED_SERVICEIMP 70%e:ps:port:tcp:80:svc:httpport:tcp:80 β†’ svc:http
FLOW_DST_PORTOBSe:fp:flow:0c699e4ab5c4:port:udp:53flow:0c699e4ab5c4 β†’ port:udp:53
FLOW_TO_HOSTOBSe:to:SESSION-68666b77cce29d40:host:192.168.1.1SESSION-68666b77cce29d40 β†’ host:192.168.1.1
flow_observed3-aryOBSe:fo:flow:df281449ac19flow:df281449ac19 β†’ host:97.178.32.239 β†’ host:192.168.1.185
HOST_GEO_ESTIMATEOBS 60%e:hg:host:13.107.226.57:geo_37.75100_-97.82200host:13.107.226.57 β†’ geo_37.75100_-97.82200
FLOW_DST_PORTOBSe:fp:flow:a912cd07306b:port:udp:41641flow:a912cd07306b β†’ port:udp:41641
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-604f49b2ccac8492:host:192.168.1.185:host:97.178.32.239SESSION-604f49b2ccac8492 β†’ host:192.168.1.185 β†’ host:97.178.32.239
FLOW_TO_HOSTOBSe:to:SESSION-e86e0a049372cc85:host:142.250.113.95SESSION-e86e0a049372cc85 β†’ host:142.250.113.95
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-04dc5a38b6cabcef:flow:05b4e5b174c0SESSION-04dc5a38b6cabcef β†’ flow:05b4e5b174c0
FLOW_DST_PORTOBSe:fp:flow:7fc08133133d:port:udp:44244flow:7fc08133133d β†’ port:udp:44244
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-bc4350b5c6d66f3f:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-bc4350b5c6d66f3f β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_QUERIED_DNSOBSe:fd:flow:660ca437efa1:dns:chatgpt.comflow:660ca437efa1 β†’ dns:chatgpt.com
flow_observed4-aryOBSe:fo:flow:bf8f4a131249flow:bf8f4a131249 β†’ host:192.168.1.185 β†’ host:172.17.0.1 β†’ port:udp:44244
FLOW_QUERIED_DNSOBSe:fd:flow:660ca437efa1:dns:remotedesktop-pa.googleapis.comflow:660ca437efa1 β†’ dns:remotedesktop-pa.googleapis.com
FLOW_DST_PORTOBSe:fp:flow:82ce7409c0ca:port:tcp:80flow:82ce7409c0ca β†’ port:tcp:80
FLOW_QUERIED_DNSOBSe:fd:flow:660ca437efa1:dns:browser.events.data.microsoft.comflow:660ca437efa1 β†’ dns:browser.events.data.microsoft.com
FLOW_TO_HOSTOBSe:to:SESSION-329be171c0b80b92:host:172.29.16.1SESSION-329be171c0b80b92 β†’ host:172.29.16.1
FLOW_FROM_HOSTOBSe:from:SESSION-348feef1c6ca6285:host:192.168.1.185SESSION-348feef1c6ca6285 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-7bf53771cd98ec17:host:192.168.1.185SESSION-7bf53771cd98ec17 β†’ host:192.168.1.185
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-f8dc5b0051ee4914:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-f8dc5b0051ee4914 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_TO_HOSTOBSe:to:SESSION-604f49b2ccac8492:host:97.178.32.239SESSION-604f49b2ccac8492 β†’ host:97.178.32.239
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 90%e:bsg:SESSION-9b68d4601d0ccd30:BSG-BEACON-4bc57cbec7cdSESSION-9b68d4601d0ccd30 β†’ BSG-BEACON-4bc57cbec7cd
flow_observed5-aryOBSe:fo:flow:300bb0be41cfflow:300bb0be41cf β†’ host:192.168.1.185 β†’ host:151.101.113.140 β†’ port:tcp:443 β†’ svc:https
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-b7d90a2138968fa3:host:209.177.156.94SESSION-b7d90a2138968fa3 β†’ host:209.177.156.94
FLOW_DST_PORTOBSe:fp:flow:779733f74ceb:port:tcp:443flow:779733f74ceb β†’ port:tcp:443
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-bcd07bc8e00bd126:flow:b41e05b0f148SESSION-bcd07bc8e00bd126 β†’ flow:b41e05b0f148
HOST_GEO_ESTIMATEOBS 60%e:hg:host:142.250.115.95:geo_37.75100_-97.82200host:142.250.115.95 β†’ geo_37.75100_-97.82200
FLOW_DST_PORTOBSe:fp:flow:4eed5ff51111:port:tcp:46407flow:4eed5ff51111 β†’ port:tcp:46407
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-dabcbf693ac9fbef:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-dabcbf693ac9fbef β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
ASN_IN_ORGOBS 80%e:ao:asn:15169:org:Google LLCasn:15169 β†’ org:Google LLC
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 90%e:bsg:SESSION-83d0b20751c23f69:BSG-BEACON-4bc57cbec7cdSESSION-83d0b20751c23f69 β†’ BSG-BEACON-4bc57cbec7cd
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-1835bee014d5b0b3:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-1835bee014d5b0b3 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_FROM_HOSTOBSe:from:SESSION-e5c653feb7de823f:host:192.168.1.185SESSION-e5c653feb7de823f β†’ host:192.168.1.185
SESSION_CONTAINS_EVENTOBSe:pe:pe:syn:SESSION-d146af26ba988e06:SESSION-d146af26ba988e06SESSION-d146af26ba988e06 β†’ pe:syn:SESSION-d146af26ba988e06
FLOW_DST_PORTOBSe:fp:flow:b41e05b0f148:port:udp:3478flow:b41e05b0f148 β†’ port:udp:3478
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-06fade4febc8462c:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-06fade4febc8462c β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-ce6603a48a5c4c37:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-ce6603a48a5c4c37 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_QUERIED_DNSOBSe:fd:flow:bf7a9427297d:dns:ctldl.windowsupdate.comflow:bf7a9427297d β†’ dns:ctldl.windowsupdate.com
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-502ccca87ddbbb24:SESSION-502ccca87ddbbb24SESSION-502ccca87ddbbb24 β†’ pe:tls:SESSION-502ccca87ddbbb24
HOST_IN_ASNOBS 85%e:ha:host:216.24.57.251:asn:397273host:216.24.57.251 β†’ asn:397273
FLOW_DST_PORTOBSe:fp:flow:65175f124256:port:tcp:443flow:65175f124256 β†’ port:tcp:443
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-741380b5a9a3a6c7:host:192.168.1.185SESSION-741380b5a9a3a6c7 β†’ host:192.168.1.185
flow_observed5-aryOBSe:fo:flow:abe950115ba3flow:abe950115ba3 β†’ host:192.168.1.185 β†’ host:13.107.226.57 β†’ port:tcp:443 β†’ svc:https
FLOW_FROM_HOSTOBSe:from:SESSION-604f49b2ccac8492:host:192.168.1.185SESSION-604f49b2ccac8492 β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-184b3698d564c9c7:host:216.24.57.7:host:192.168.1.185SESSION-184b3698d564c9c7 β†’ host:216.24.57.7 β†’ host:192.168.1.185
flow_observed4-aryOBSe:fo:flow:4f5810e72704flow:4f5810e72704 β†’ host:192.168.1.185 β†’ host:192.73.244.245 β†’ port:udp:3478
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-8c7ddbb6fe26a9a9:host:216.239.32.223SESSION-8c7ddbb6fe26a9a9 β†’ host:216.239.32.223
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-c8f5f362e7c0c5c8:host:216.24.57.251SESSION-c8f5f362e7c0c5c8 β†’ host:216.24.57.251
HOST_GEO_ESTIMATEOBS 60%e:hg:host:167.235.217.196:geo_50.47770_12.36490host:167.235.217.196 β†’ geo_50.47770_12.36490
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-cbcc97483386b4f3:host:104.18.32.47SESSION-cbcc97483386b4f3 β†’ host:104.18.32.47
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-e6ad21d692182871:flow:cb933110cf94SESSION-e6ad21d692182871 β†’ flow:cb933110cf94
FLOW_DST_PORTOBSe:fp:flow:189be888c3af:port:tcp:443flow:189be888c3af β†’ port:tcp:443
HOST_GEO_ESTIMATEOBS 60%e:hg:host:192.200.0.112:geo_43.63190_-79.37160host:192.200.0.112 β†’ geo_43.63190_-79.37160
FLOW_FROM_HOSTOBSe:from:SESSION-5419af02605f5da4:host:192.168.1.185SESSION-5419af02605f5da4 β†’ host:192.168.1.185
ASN_IN_ORGOBS 80%e:ao:asn:396982:org:Google LLCasn:396982 β†’ org:Google LLC
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-e6729d0ebc579395:host:192.168.1.185:host:97.178.32.239SESSION-e6729d0ebc579395 β†’ host:192.168.1.185 β†’ host:97.178.32.239
flow_observed5-aryOBSe:fo:flow:d84a13678d67flow:d84a13678d67 β†’ host:192.168.1.185 β†’ host:142.250.113.95 β†’ port:udp:443 β†’ svc:https
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-04dc5a38b6cabcef:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-04dc5a38b6cabcef β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-06fade4febc8462c:flow:189be888c3afSESSION-06fade4febc8462c β†’ flow:189be888c3af
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-d7f6ed06cf3ab18b:host:192.168.1.185SESSION-d7f6ed06cf3ab18b β†’ host:192.168.1.185
HOST_IN_ASNOBS 85%e:ha:host:97.178.32.239:asn:6167host:97.178.32.239 β†’ asn:6167
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-3cb87513d2c7904f:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-3cb87513d2c7904f β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-502ccca87ddbbb24:host:192.168.1.185:host:35.190.80.1SESSION-502ccca87ddbbb24 β†’ host:192.168.1.185 β†’ host:35.190.80.1
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-8394aca80c2a0790:host:192.168.1.185:host:52.182.143.215SESSION-8394aca80c2a0790 β†’ host:192.168.1.185 β†’ host:52.182.143.215
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-ea1d23994577309a:host:192.168.1.185SESSION-ea1d23994577309a β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:65c7de267840:port:udp:5351flow:65c7de267840 β†’ port:udp:5351
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-65e185b6eab54d6a:flow:65c7de267840SESSION-65e185b6eab54d6a β†’ flow:65c7de267840
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-c8f5f362e7c0c5c8:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-c8f5f362e7c0c5c8 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-d146af26ba988e06:host:104.18.32.47SESSION-d146af26ba988e06 β†’ host:104.18.32.47
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e6ad21d692182871:host:192.168.1.185SESSION-e6ad21d692182871 β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-8c7ddbb6fe26a9a9:host:216.239.32.223:host:192.168.1.185SESSION-8c7ddbb6fe26a9a9 β†’ host:216.239.32.223 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-bc4350b5c6d66f3f:host:192.168.1.185SESSION-bc4350b5c6d66f3f β†’ host:192.168.1.185
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-c4d9c40a7fec56be:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-c4d9c40a7fec56be β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-06fade4febc8462c:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-06fade4febc8462c β†’ BSG-HORIZ_SCAN-cd2c52661c4b
HOST_GEO_ESTIMATEOBS 60%e:hg:host:52.110.6.13:geo_29.42270_-98.49270host:52.110.6.13 β†’ geo_29.42270_-98.49270
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-9c845bfb2b534b59:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-9c845bfb2b534b59 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-65e185b6eab54d6a:host:192.168.1.185SESSION-65e185b6eab54d6a β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-9dab8edd40d14d9d:host:192.168.1.185SESSION-9dab8edd40d14d9d β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-348feef1c6ca6285:host:192.168.1.185:host:151.101.113.140SESSION-348feef1c6ca6285 β†’ host:192.168.1.185 β†’ host:151.101.113.140
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e5c653feb7de823f:host:192.168.1.185SESSION-e5c653feb7de823f β†’ host:192.168.1.185
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-d146af26ba988e06:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-d146af26ba988e06 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
FLOW_DST_PORTOBSe:fp:flow:3d20532e84ed:port:udp:443flow:3d20532e84ed β†’ port:udp:443
FLOW_FROM_HOSTOBSe:from:SESSION-81e5b5be161de125:host:192.168.1.185SESSION-81e5b5be161de125 β†’ host:192.168.1.185
flow_observed4-aryOBSe:fo:flow:682d5368c69eflow:682d5368c69e β†’ host:192.168.1.185 β†’ host:97.178.32.239 β†’ port:udp:1050
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-9c845bfb2b534b59:host:192.168.1.185SESSION-9c845bfb2b534b59 β†’ host:192.168.1.185
flow_observed4-aryOBSe:fo:flow:b41e05b0f148flow:b41e05b0f148 β†’ host:192.168.1.185 β†’ host:209.177.158.246 β†’ port:udp:3478
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-65a9e51617aa2712:host:199.165.136.100SESSION-65a9e51617aa2712 β†’ host:199.165.136.100
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-e5c653feb7de823f:host:192.168.1.185:host:192.73.243.135SESSION-e5c653feb7de823f β†’ host:192.168.1.185 β†’ host:192.73.243.135
flow_observed5-aryOBSe:fo:flow:bab9257727f6flow:bab9257727f6 β†’ host:192.168.1.185 β†’ host:23.219.160.5 β†’ port:udp:443 β†’ svc:https
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-36cd4459caa078a9:flow:5a246bdf60e4SESSION-36cd4459caa078a9 β†’ flow:5a246bdf60e4
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-9c85e6a530e7f20f:host:192.168.1.185SESSION-9c85e6a530e7f20f β†’ host:192.168.1.185
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-de97a19f0937505c:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-de97a19f0937505c β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-7bf53771cd98ec17:flow:f6fc82e11042SESSION-7bf53771cd98ec17 β†’ flow:f6fc82e11042
HOST_IN_ASNOBS 85%e:ha:host:23.219.160.5:asn:20940host:23.219.160.5 β†’ asn:20940
FLOW_TO_HOSTOBSe:to:SESSION-3cb87513d2c7904f:host:192.168.1.1SESSION-3cb87513d2c7904f β†’ host:192.168.1.1
FLOW_TO_HOSTOBSe:to:SESSION-58f9cafe500f64ad:host:192.168.1.1SESSION-58f9cafe500f64ad β†’ host:192.168.1.1
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-200a1edeb5081c1b:flow:d479ce3b7365SESSION-200a1edeb5081c1b β†’ flow:d479ce3b7365
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-de97a19f0937505c:host:104.18.1.62:host:192.168.1.185SESSION-de97a19f0937505c β†’ host:104.18.1.62 β†’ host:192.168.1.185
flow_observed4-aryOBSe:fo:flow:0523b90826b8flow:0523b90826b8 β†’ host:192.200.0.112 β†’ host:192.168.1.185 β†’ port:tcp:51645
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e0cdf80170e46e9e:host:192.168.1.185SESSION-e0cdf80170e46e9e β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-8c7ddbb6fe26a9a9:host:192.168.1.185SESSION-8c7ddbb6fe26a9a9 β†’ host:192.168.1.185
flow_observed4-aryOBSe:fo:flow:26faad66f81eflow:26faad66f81e β†’ host:192.168.1.185 β†’ host:172.18.0.1 β†’ port:udp:44244
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-05305b96b26cdffd:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-05305b96b26cdffd β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_DST_PORTOBSe:fp:flow:d83699920b5b:port:tcp:443flow:d83699920b5b β†’ port:tcp:443
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-e53f703ab7b48a77:flow:9aa8161296f7SESSION-e53f703ab7b48a77 β†’ flow:9aa8161296f7
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-7dbcb4428a9e5e71:host:192.168.1.185SESSION-7dbcb4428a9e5e71 β†’ host:192.168.1.185
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-17e440ba96a7a7b5:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-17e440ba96a7a7b5 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-787a71cfd2c6f769:host:162.159.128.61:host:192.168.1.185SESSION-787a71cfd2c6f769 β†’ host:162.159.128.61 β†’ host:192.168.1.185
HOST_GEO_ESTIMATEOBS 60%e:hg:host:150.171.28.10:geo_37.75100_-97.82200host:150.171.28.10 β†’ geo_37.75100_-97.82200
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-68666b77cce29d40:host:192.168.1.1SESSION-68666b77cce29d40 β†’ host:192.168.1.1
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-65e185b6eab54d6a:host:192.168.1.185:host:192.168.1.1SESSION-65e185b6eab54d6a β†’ host:192.168.1.185 β†’ host:192.168.1.1
FLOW_FROM_HOSTOBSe:from:SESSION-36cd4459caa078a9:host:192.168.1.185SESSION-36cd4459caa078a9 β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:341692033057:port:udp:41641flow:341692033057 β†’ port:udp:41641
flow_observed4-aryOBSe:fo:flow:46f60ddc23a2flow:46f60ddc23a2 β†’ host:192.168.1.185 β†’ host:192.168.1.1 β†’ port:tcp:46407
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-22420a928847cfad:host:192.168.1.185SESSION-22420a928847cfad β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:478de54cd94a:port:udp:31036flow:478de54cd94a β†’ port:udp:31036
HOST_GEO_ESTIMATEOBS 60%e:hg:host:192.73.248.83:geo_32.77970_-96.80220host:192.73.248.83 β†’ geo_32.77970_-96.80220
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-055fd962754012c2:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-055fd962754012c2 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-787a71cfd2c6f769:SESSION-787a71cfd2c6f769SESSION-787a71cfd2c6f769 β†’ pe:tls:SESSION-787a71cfd2c6f769
SESSION_CONTAINS_EVENTOBSe:pe:pe:dns:SESSION-68666b77cce29d40:SESSION-68666b77cce29d40SESSION-68666b77cce29d40 β†’ pe:dns:SESSION-68666b77cce29d40
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-7b2b00e0ceb88c09:host:20.62.59.32SESSION-7b2b00e0ceb88c09 β†’ host:20.62.59.32
flow_observed4-aryOBSe:fo:flow:c44b4fd56f98flow:c44b4fd56f98 β†’ host:216.239.32.223 β†’ host:192.168.1.185 β†’ port:udp:60920
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-055fd962754012c2:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-055fd962754012c2 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_FROM_HOSTOBSe:from:SESSION-fa034e5132aecf5b:host:192.168.1.185SESSION-fa034e5132aecf5b β†’ host:192.168.1.185
flow_observed4-aryOBSe:fo:flow:f6fc82e11042flow:f6fc82e11042 β†’ host:192.168.1.185 β†’ host:192.168.1.1 β†’ port:udp:5351
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-716de9787a03c45e:host:23.219.160.5SESSION-716de9787a03c45e β†’ host:23.219.160.5
HOST_GEO_ESTIMATEOBS 60%e:hg:host:151.101.113.140:geo_32.77970_-96.80220host:151.101.113.140 β†’ geo_32.77970_-96.80220
FLOW_TO_HOSTOBSe:to:SESSION-348feef1c6ca6285:host:151.101.113.140SESSION-348feef1c6ca6285 β†’ host:151.101.113.140
FLOW_TO_HOSTOBSe:to:SESSION-99947e3aab494326:host:192.168.1.185SESSION-99947e3aab494326 β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-934baa2aae663ceb:host:151.101.113.140SESSION-934baa2aae663ceb β†’ host:151.101.113.140
FLOW_TO_HOSTOBSe:to:SESSION-4cf06bd9f9c07bb4:host:97.178.32.239SESSION-4cf06bd9f9c07bb4 β†’ host:97.178.32.239
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-1065a64ded6cc44c:flow:7fc08133133dSESSION-1065a64ded6cc44c β†’ flow:7fc08133133d
ASN_IN_ORGOBS 80%e:ao:asn:8075:org:Microsoft Corporationasn:8075 β†’ org:Microsoft Corporation
HOST_GEO_ESTIMATEOBS 60%e:hg:host:35.190.80.1:geo_37.75100_-97.82200host:35.190.80.1 β†’ geo_37.75100_-97.82200
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-10cf97843d85c279:host:192.168.1.185:host:209.177.156.94SESSION-10cf97843d85c279 β†’ host:192.168.1.185 β†’ host:209.177.156.94
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-2014bf32e6dab59e:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-2014bf32e6dab59e β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-7b2b00e0ceb88c09:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-7b2b00e0ceb88c09 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
FLOW_FROM_HOSTOBSe:from:SESSION-934baa2aae663ceb:host:192.168.1.185SESSION-934baa2aae663ceb β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-9c845bfb2b534b59:host:150.171.28.10SESSION-9c845bfb2b534b59 β†’ host:150.171.28.10
FLOW_TO_HOSTOBSe:to:SESSION-1ea83345da6e2df0:host:224.0.0.22SESSION-1ea83345da6e2df0 β†’ host:224.0.0.22
ASN_IN_ORGOBS 80%e:ao:asn:16509:org:Amazon.com, Inc.asn:16509 β†’ org:Amazon.com, Inc.
HOST_GEO_ESTIMATEOBS 60%e:hg:host:216.24.57.7:geo_37.75100_-97.82200host:216.24.57.7 β†’ geo_37.75100_-97.82200
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-ce6603a48a5c4c37:host:192.168.1.185SESSION-ce6603a48a5c4c37 β†’ host:192.168.1.185
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-b7338ba843b2dafa:SESSION-b7338ba843b2dafaSESSION-b7338ba843b2dafa β†’ pe:tls:SESSION-b7338ba843b2dafa
FLOW_FROM_HOSTOBSe:from:SESSION-9c85e6a530e7f20f:host:192.168.1.185SESSION-9c85e6a530e7f20f β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-4cf06bd9f9c07bb4:host:192.168.1.185SESSION-4cf06bd9f9c07bb4 β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-5673cdc8e15ecc28:host:167.235.217.196:host:192.168.1.185SESSION-5673cdc8e15ecc28 β†’ host:167.235.217.196 β†’ host:192.168.1.185
SESSION_CONTAINS_EVENTOBSe:pe:pe:syn:SESSION-83d0b20751c23f69:SESSION-83d0b20751c23f69SESSION-83d0b20751c23f69 β†’ pe:syn:SESSION-83d0b20751c23f69
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-ce6603a48a5c4c37:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-ce6603a48a5c4c37 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-741380b5a9a3a6c7:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-741380b5a9a3a6c7 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
flow_observed4-aryOBSe:fo:flow:137f07aaadb4flow:137f07aaadb4 β†’ host:192.168.1.185 β†’ host:97.178.32.239 β†’ port:udp:41641
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-741380b5a9a3a6c7:SESSION-741380b5a9a3a6c7SESSION-741380b5a9a3a6c7 β†’ pe:tls:SESSION-741380b5a9a3a6c7
FLOW_DST_PORTOBSe:fp:flow:f3b81336df74:port:tcp:443flow:f3b81336df74 β†’ port:tcp:443
FLOW_TO_HOSTOBSe:to:SESSION-36cd4459caa078a9:host:135.234.174.40SESSION-36cd4459caa078a9 β†’ host:135.234.174.40
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-de97a19f0937505c:SESSION-de97a19f0937505cSESSION-de97a19f0937505c β†’ pe:tls:SESSION-de97a19f0937505c
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-fa034e5132aecf5b:host:192.168.1.185:host:13.107.226.57SESSION-fa034e5132aecf5b β†’ host:192.168.1.185 β†’ host:13.107.226.57
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-441bb1af5ec88ffb:host:76.76.21.22SESSION-441bb1af5ec88ffb β†’ host:76.76.21.22
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-5419af02605f5da4:flow:341692033057SESSION-5419af02605f5da4 β†’ flow:341692033057
flow_observed5-aryOBSe:fo:flow:ab2fda60ec38flow:ab2fda60ec38 β†’ host:192.168.1.185 β†’ host:150.171.28.10 β†’ port:tcp:443 β†’ svc:https
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-2681df7af5f78270:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-2681df7af5f78270 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-bc4350b5c6d66f3f:host:34.111.31.13SESSION-bc4350b5c6d66f3f β†’ host:34.111.31.13
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-99947e3aab494326:SESSION-99947e3aab494326SESSION-99947e3aab494326 β†’ pe:tls:SESSION-99947e3aab494326
FLOW_FROM_HOSTOBSe:from:SESSION-8394aca80c2a0790:host:192.168.1.185SESSION-8394aca80c2a0790 β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:5b983251f483:port:tcp:52133flow:5b983251f483 β†’ port:tcp:52133
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-8fd6ad39adf47a18:host:104.18.36.216SESSION-8fd6ad39adf47a18 β†’ host:104.18.36.216
FLOW_FROM_HOSTOBSe:from:SESSION-1835bee014d5b0b3:host:192.168.1.185SESSION-1835bee014d5b0b3 β†’ host:192.168.1.185
FLOW_HTTP_HOSTOBSe:fh:flow:82ce7409c0ca:http_host:ctldl.windowsupdate.comflow:82ce7409c0ca β†’ http_host:ctldl.windowsupdate.com
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-716de9787a03c45e:host:192.168.1.185SESSION-716de9787a03c45e β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-858ec5d25a7b6232:host:192.168.1.185:host:97.178.32.239SESSION-858ec5d25a7b6232 β†’ host:192.168.1.185 β†’ host:97.178.32.239
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-c8f5f362e7c0c5c8:flow:e36e1209129dSESSION-c8f5f362e7c0c5c8 β†’ flow:e36e1209129d
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-bc4350b5c6d66f3f:flow:c0b4f157e073SESSION-bc4350b5c6d66f3f β†’ flow:c0b4f157e073
ASN_IN_ORGOBS 80%e:ao:asn:397273:org:Renderasn:397273 β†’ org:Render
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-5673cdc8e15ecc28:host:192.168.1.185SESSION-5673cdc8e15ecc28 β†’ host:192.168.1.185
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-423d6f8fa2a9f7bc:SESSION-423d6f8fa2a9f7bcSESSION-423d6f8fa2a9f7bc β†’ pe:tls:SESSION-423d6f8fa2a9f7bc
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-17e440ba96a7a7b5:flow:e34282443dabSESSION-17e440ba96a7a7b5 β†’ flow:e34282443dab
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-a019cb392bc23a7a:host:192.168.1.185:host:199.165.136.100SESSION-a019cb392bc23a7a β†’ host:192.168.1.185 β†’ host:199.165.136.100
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-21bfec774060aafb:flow:46f60ddc23a2SESSION-21bfec774060aafb β†’ flow:46f60ddc23a2
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-184b3698d564c9c7:host:192.168.1.185SESSION-184b3698d564c9c7 β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-7b2b00e0ceb88c09:host:192.168.1.185:host:20.62.59.32SESSION-7b2b00e0ceb88c09 β†’ host:192.168.1.185 β†’ host:20.62.59.32
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-99947e3aab494326:host:192.200.0.112:host:192.168.1.185SESSION-99947e3aab494326 β†’ host:192.200.0.112 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-a019cb392bc23a7a:host:192.168.1.185SESSION-a019cb392bc23a7a β†’ host:192.168.1.185
flow_observed4-aryOBSe:fo:flow:0380e0cd29dcflow:0380e0cd29dc β†’ host:104.18.39.21 β†’ host:192.168.1.185 β†’ port:tcp:52640
flow_observed4-aryOBSe:fo:flow:d479ce3b7365flow:d479ce3b7365 β†’ host:52.110.6.13 β†’ host:192.168.1.185 β†’ port:tcp:54629
FLOW_DST_PORTOBSe:fp:flow:00f4e10d6ac7:port:tcp:43844flow:00f4e10d6ac7 β†’ port:tcp:43844
HOST_IN_ASNOBS 85%e:ha:host:151.101.112.217:asn:54113host:151.101.112.217 β†’ asn:54113
FLOW_DST_PORTOBSe:fp:flow:d84a13678d67:port:udp:443flow:d84a13678d67 β†’ port:udp:443
HOST_IN_ASNOBS 85%e:ha:host:135.234.174.40:asn:8075host:135.234.174.40 β†’ asn:8075
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-441bb1af5ec88ffb:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-441bb1af5ec88ffb β†’ BSG-HORIZ_SCAN-cd2c52661c4b
FLOW_TO_HOSTOBSe:to:SESSION-22420a928847cfad:host:192.168.1.1SESSION-22420a928847cfad β†’ host:192.168.1.1
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-348feef1c6ca6285:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-348feef1c6ca6285 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
flow_observed4-aryOBSe:fo:flow:027ad06c15d5flow:027ad06c15d5 β†’ host:104.18.36.216 β†’ host:192.168.1.185 β†’ port:tcp:55880
HOST_GEO_ESTIMATEOBS 60%e:hg:host:97.178.32.239:geo_29.82840_-95.46960host:97.178.32.239 β†’ geo_29.82840_-95.46960
FLOW_FROM_HOSTOBSe:from:SESSION-e6ad21d692182871:host:192.168.1.185SESSION-e6ad21d692182871 β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-e53f703ab7b48a77:host:199.165.136.100SESSION-e53f703ab7b48a77 β†’ host:199.165.136.100
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-e5c653feb7de823f:flow:62d01d1bf747SESSION-e5c653feb7de823f β†’ flow:62d01d1bf747
HOST_IN_ASNOBS 85%e:ha:host:216.239.32.223:asn:15169host:216.239.32.223 β†’ asn:15169
FLOW_TO_HOSTOBSe:to:SESSION-21bfec774060aafb:host:192.168.1.1SESSION-21bfec774060aafb β†’ host:192.168.1.1
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-329be171c0b80b92:host:192.168.1.185SESSION-329be171c0b80b92 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-3cb87513d2c7904f:host:192.168.1.185SESSION-3cb87513d2c7904f β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-741380b5a9a3a6c7:host:172.64.151.22:host:192.168.1.185SESSION-741380b5a9a3a6c7 β†’ host:172.64.151.22 β†’ host:192.168.1.185
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-b7338ba843b2dafa:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-b7338ba843b2dafa β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_CONTAINS_EVENTOBSe:pe:pe:syn:SESSION-9b68d4601d0ccd30:SESSION-9b68d4601d0ccd30SESSION-9b68d4601d0ccd30 β†’ pe:syn:SESSION-9b68d4601d0ccd30
FLOW_TO_HOSTOBSe:to:SESSION-a019cb392bc23a7a:host:199.165.136.100SESSION-a019cb392bc23a7a β†’ host:199.165.136.100
flow_observed4-aryOBSe:fo:flow:9cc54a60d88aflow:9cc54a60d88a β†’ host:167.235.217.196 β†’ host:192.168.1.185 β†’ port:tcp:54986
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-329be171c0b80b92:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-329be171c0b80b92 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
flow_observed4-aryOBSe:fo:flow:62d01d1bf747flow:62d01d1bf747 β†’ host:192.168.1.185 β†’ host:192.73.243.135 β†’ port:udp:3478
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-65e185b6eab54d6a:host:192.168.1.1SESSION-65e185b6eab54d6a β†’ host:192.168.1.1
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-81e5b5be161de125:flow:82ce7409c0caSESSION-81e5b5be161de125 β†’ flow:82ce7409c0ca
FLOW_TO_HOSTOBSe:to:SESSION-858ec5d25a7b6232:host:97.178.32.239SESSION-858ec5d25a7b6232 β†’ host:97.178.32.239
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-04dc5a38b6cabcef:host:167.235.217.196:host:192.168.1.185SESSION-04dc5a38b6cabcef β†’ host:167.235.217.196 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-65a9e51617aa2712:host:192.168.1.185SESSION-65a9e51617aa2712 β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-1065a64ded6cc44c:host:172.19.0.1SESSION-1065a64ded6cc44c β†’ host:172.19.0.1
flow_observed3-aryOBSe:fo:flow:bf7a9427297dflow:bf7a9427297d β†’ host:192.168.1.185 β†’ host:192.168.1.1
FLOW_FROM_HOSTOBSe:from:SESSION-9dab8edd40d14d9d:host:104.18.39.21SESSION-9dab8edd40d14d9d β†’ host:104.18.39.21
FLOW_DST_PORTOBSe:fp:flow:fdf049da8b14:port:udp:3478flow:fdf049da8b14 β†’ port:udp:3478
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-08bfd8721a383a39:host:192.168.1.1SESSION-08bfd8721a383a39 β†’ host:192.168.1.1
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-2014bf32e6dab59e:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-2014bf32e6dab59e β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_FROM_HOSTOBSe:from:SESSION-9b68d4601d0ccd30:host:192.168.1.185SESSION-9b68d4601d0ccd30 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-d146af26ba988e06:host:192.168.1.185SESSION-d146af26ba988e06 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-5673cdc8e15ecc28:host:167.235.217.196SESSION-5673cdc8e15ecc28 β†’ host:167.235.217.196
FLOW_FROM_HOSTOBSe:from:SESSION-7dbcb4428a9e5e71:host:192.168.1.185SESSION-7dbcb4428a9e5e71 β†’ host:192.168.1.185
HOST_IN_ASNOBS 85%e:ha:host:35.190.80.1:asn:396982host:35.190.80.1 β†’ asn:396982
flow_observed4-aryOBSe:fo:flow:03d3562fa35fflow:03d3562fa35f β†’ host:192.168.1.185 β†’ host:97.178.32.239 β†’ port:udp:52243
FLOW_TO_HOSTOBSe:to:SESSION-b7d90a2138968fa3:host:192.168.1.185SESSION-b7d90a2138968fa3 β†’ host:192.168.1.185
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-cbcc97483386b4f3:SESSION-cbcc97483386b4f3SESSION-cbcc97483386b4f3 β†’ pe:tls:SESSION-cbcc97483386b4f3
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-f32643b41a201d5b:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-f32643b41a201d5b β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-3cb87513d2c7904f:host:192.168.1.1SESSION-3cb87513d2c7904f β†’ host:192.168.1.1
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 50%e:bsg:SESSION-b7d90a2138968fa3:BSG-DATA_EXFIL-e7f288856e4cSESSION-b7d90a2138968fa3 β†’ BSG-DATA_EXFIL-e7f288856e4c
FLOW_FROM_HOSTOBSe:from:SESSION-bcd07bc8e00bd126:host:192.168.1.185SESSION-bcd07bc8e00bd126 β†’ host:192.168.1.185
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-81e5b5be161de125:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-81e5b5be161de125 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_FROM_HOSTOBSe:from:SESSION-502ccca87ddbbb24:host:192.168.1.185SESSION-502ccca87ddbbb24 β†’ host:192.168.1.185
flow_observed5-aryOBSe:fo:flow:cb933110cf94flow:cb933110cf94 β†’ host:192.168.1.185 β†’ host:199.165.136.100 β†’ port:tcp:443 β†’ svc:https
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-329be171c0b80b92:host:192.168.1.185:host:172.29.16.1SESSION-329be171c0b80b92 β†’ host:192.168.1.185 β†’ host:172.29.16.1
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-ea1d23994577309a:host:104.18.22.222:host:192.168.1.185SESSION-ea1d23994577309a β†’ host:104.18.22.222 β†’ host:192.168.1.185
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-c4d9c40a7fec56be:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-c4d9c40a7fec56be β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
flow_observed4-aryOBSe:fo:flow:341692033057flow:341692033057 β†’ host:192.168.1.185 β†’ host:97.178.32.239 β†’ port:udp:41641
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 90%e:bsg:SESSION-934baa2aae663ceb:BSG-BEACON-3fa1dca5627cSESSION-934baa2aae663ceb β†’ BSG-BEACON-3fa1dca5627c
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-36cd4459caa078a9:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-36cd4459caa078a9 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-05305b96b26cdffd:SESSION-05305b96b26cdffdSESSION-05305b96b26cdffd β†’ pe:tls:SESSION-05305b96b26cdffd
FLOW_DST_PORTOBSe:fp:flow:495f7c8d94fd:port:tcp:43844flow:495f7c8d94fd β†’ port:tcp:43844
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e5c653feb7de823f:host:192.73.243.135SESSION-e5c653feb7de823f β†’ host:192.73.243.135
FLOW_TO_HOSTOBSe:to:SESSION-502ccca87ddbbb24:host:35.190.80.1SESSION-502ccca87ddbbb24 β†’ host:35.190.80.1
FLOW_DST_PORTOBSe:fp:flow:f5abaef54664:port:tcp:46407flow:f5abaef54664 β†’ port:tcp:46407
ASN_IN_ORGOBS 80%e:ao:asn:54113:org:Fastly, Inc.asn:54113 β†’ org:Fastly, Inc.
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-17e440ba96a7a7b5:host:142.250.115.95SESSION-17e440ba96a7a7b5 β†’ host:142.250.115.95
flow_observed4-aryOBSe:fo:flow:05b4e5b174c0flow:05b4e5b174c0 β†’ host:167.235.217.196 β†’ host:192.168.1.185 β†’ port:tcp:54986
FLOW_TO_HOSTOBSe:to:SESSION-81e5b5be161de125:host:151.101.114.172SESSION-81e5b5be161de125 β†’ host:151.101.114.172
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e6ad21d692182871:host:199.165.136.100SESSION-e6ad21d692182871 β†’ host:199.165.136.100
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-17e440ba96a7a7b5:host:192.168.1.185SESSION-17e440ba96a7a7b5 β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-17e440ba96a7a7b5:host:142.250.115.95SESSION-17e440ba96a7a7b5 β†’ host:142.250.115.95
FLOW_FROM_HOSTOBSe:from:SESSION-1065a64ded6cc44c:host:192.168.1.185SESSION-1065a64ded6cc44c β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-e565a4fbf5cff09b:host:192.73.248.83SESSION-e565a4fbf5cff09b β†’ host:192.73.248.83
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e53f703ab7b48a77:host:199.165.136.100SESSION-e53f703ab7b48a77 β†’ host:199.165.136.100
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-f32643b41a201d5b:host:192.168.1.185SESSION-f32643b41a201d5b β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-86bc6b9e53c222b0:host:192.168.1.185SESSION-86bc6b9e53c222b0 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-f32643b41a201d5b:host:209.177.158.246SESSION-f32643b41a201d5b β†’ host:209.177.158.246
flow_observed4-aryOBSe:fo:flow:f5abaef54664flow:f5abaef54664 β†’ host:192.168.1.185 β†’ host:192.168.1.1 β†’ port:tcp:46407
FLOW_TLS_SNIOBSe:fs:flow:f25397a8d5d5:tls_sni:chatgpt.comflow:f25397a8d5d5 β†’ tls_sni:chatgpt.com
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-06fade4febc8462c:host:192.168.1.185SESSION-06fade4febc8462c β†’ host:192.168.1.185
SESSION_CONTAINS_EVENTOBSe:pe:pe:syn:SESSION-06fade4febc8462c:SESSION-06fade4febc8462cSESSION-06fade4febc8462c β†’ pe:syn:SESSION-06fade4febc8462c
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-8394aca80c2a0790:host:52.182.143.215SESSION-8394aca80c2a0790 β†’ host:52.182.143.215
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-04dc5a38b6cabcef:SESSION-04dc5a38b6cabcefSESSION-04dc5a38b6cabcef β†’ pe:tls:SESSION-04dc5a38b6cabcef
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-5673cdc8e15ecc28:SESSION-5673cdc8e15ecc28SESSION-5673cdc8e15ecc28 β†’ pe:tls:SESSION-5673cdc8e15ecc28
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-934baa2aae663ceb:SESSION-934baa2aae663cebSESSION-934baa2aae663ceb β†’ pe:tls:SESSION-934baa2aae663ceb
flow_observed5-aryOBSe:fo:flow:65175f124256flow:65175f124256 β†’ host:192.168.1.185 β†’ host:199.165.136.100 β†’ port:tcp:443 β†’ svc:https
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-716de9787a03c45e:host:192.168.1.185:host:23.219.160.5SESSION-716de9787a03c45e β†’ host:192.168.1.185 β†’ host:23.219.160.5
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-1835bee014d5b0b3:flow:bf8f4a131249SESSION-1835bee014d5b0b3 β†’ flow:bf8f4a131249
FLOW_FROM_HOSTOBSe:from:SESSION-65e185b6eab54d6a:host:192.168.1.185SESSION-65e185b6eab54d6a β†’ host:192.168.1.185
flow_observed5-aryOBSe:fo:flow:a3f08c1df1f5flow:a3f08c1df1f5 β†’ host:192.168.1.185 β†’ host:192.73.248.83 β†’ port:tcp:443 β†’ svc:https
FLOW_DST_PORTOBSe:fp:flow:ef26bc2c964d:port:tcp:62104flow:ef26bc2c964d β†’ port:tcp:62104
flow_observed5-aryOBSe:fo:flow:82ce7409c0caflow:82ce7409c0ca β†’ host:192.168.1.185 β†’ host:151.101.114.172 β†’ port:tcp:80 β†’ svc:http
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-b7338ba843b2dafa:host:192.168.1.185SESSION-b7338ba843b2dafa β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:007f4ea11c64:port:tcp:443flow:007f4ea11c64 β†’ port:tcp:443
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-9dab8edd40d14d9d:host:104.18.39.21SESSION-9dab8edd40d14d9d β†’ host:104.18.39.21
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-cbcc97483386b4f3:flow:7986b2093729SESSION-cbcc97483386b4f3 β†’ flow:7986b2093729
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-22420a928847cfad:host:192.168.1.1SESSION-22420a928847cfad β†’ host:192.168.1.1
FLOW_FROM_HOSTOBSe:from:SESSION-8c7ddbb6fe26a9a9:host:216.239.32.223SESSION-8c7ddbb6fe26a9a9 β†’ host:216.239.32.223
flow_observed5-aryOBSe:fo:flow:3d20532e84edflow:3d20532e84ed β†’ host:192.168.1.185 β†’ host:23.219.160.5 β†’ port:udp:443 β†’ svc:https
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-7dbcb4428a9e5e71:host:209.177.156.94SESSION-7dbcb4428a9e5e71 β†’ host:209.177.156.94
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-1ea83345da6e2df0:host:192.168.1.165:host:224.0.0.22SESSION-1ea83345da6e2df0 β†’ host:192.168.1.165 β†’ host:224.0.0.22
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-055fd962754012c2:SESSION-055fd962754012c2SESSION-055fd962754012c2 β†’ pe:tls:SESSION-055fd962754012c2
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-cbcc97483386b4f3:host:192.168.1.185:host:104.18.32.47SESSION-cbcc97483386b4f3 β†’ host:192.168.1.185 β†’ host:104.18.32.47
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-e6ad21d692182871:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-e6ad21d692182871 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-8394aca80c2a0790:host:192.168.1.185SESSION-8394aca80c2a0790 β†’ host:192.168.1.185
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-184b3698d564c9c7:SESSION-184b3698d564c9c7SESSION-184b3698d564c9c7 β†’ pe:tls:SESSION-184b3698d564c9c7
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-5419af02605f5da4:host:192.168.1.185SESSION-5419af02605f5da4 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-e53f703ab7b48a77:host:192.168.1.185SESSION-e53f703ab7b48a77 β†’ host:192.168.1.185
HOST_IN_ASNOBS 85%e:ha:host:104.208.203.89:asn:8075host:104.208.203.89 β†’ asn:8075
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-22420a928847cfad:host:192.168.1.185:host:192.168.1.1SESSION-22420a928847cfad β†’ host:192.168.1.185 β†’ host:192.168.1.1
FLOW_DST_PORTOBSe:fp:flow:abe950115ba3:port:tcp:443flow:abe950115ba3 β†’ port:tcp:443
FLOW_DST_PORTOBSe:fp:flow:46c89f86a16a:port:udp:443flow:46c89f86a16a β†’ port:udp:443
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-e25097cf84c7b988:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-e25097cf84c7b988 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-f32643b41a201d5b:host:192.168.1.185:host:209.177.158.246SESSION-f32643b41a201d5b β†’ host:192.168.1.185 β†’ host:209.177.158.246
HOST_GEO_ESTIMATEOBS 60%e:hg:host:192.73.244.245:geo_34.05440_-118.24400host:192.73.244.245 β†’ geo_34.05440_-118.24400
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-7dbcb4428a9e5e71:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-7dbcb4428a9e5e71 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-184b3698d564c9c7:host:216.24.57.7SESSION-184b3698d564c9c7 β†’ host:216.24.57.7
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-8394aca80c2a0790:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-8394aca80c2a0790 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-9c845bfb2b534b59:host:192.168.1.185:host:150.171.28.10SESSION-9c845bfb2b534b59 β†’ host:192.168.1.185 β†’ host:150.171.28.10
FLOW_DST_PORTOBSe:fp:flow:dd3dd13e1b60:port:udp:3478flow:dd3dd13e1b60 β†’ port:udp:3478
FLOW_TO_HOSTOBSe:to:SESSION-ce6603a48a5c4c37:host:23.219.160.5SESSION-ce6603a48a5c4c37 β†’ host:23.219.160.5
FLOW_TO_HOSTOBSe:to:SESSION-1f115942b61afe54:host:192.73.244.245SESSION-1f115942b61afe54 β†’ host:192.73.244.245
FLOW_DST_PORTOBSe:fp:flow:f25397a8d5d5:port:tcp:443flow:f25397a8d5d5 β†’ port:tcp:443
FLOW_FROM_HOSTOBSe:from:SESSION-21bfec774060aafb:host:192.168.1.185SESSION-21bfec774060aafb β†’ host:192.168.1.185
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-423d6f8fa2a9f7bc:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-423d6f8fa2a9f7bc β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-ea1d23994577309a:host:104.18.22.222SESSION-ea1d23994577309a β†’ host:104.18.22.222
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-ea1d23994577309a:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-ea1d23994577309a β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-1f115942b61afe54:host:192.168.1.185SESSION-1f115942b61afe54 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e53f703ab7b48a77:host:192.168.1.185SESSION-e53f703ab7b48a77 β†’ host:192.168.1.185
PORT_IMPLIED_SERVICEIMP 70%e:ps:port:udp:443:svc:httpsport:udp:443 β†’ svc:https
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-65a9e51617aa2712:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-65a9e51617aa2712 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-bcd07bc8e00bd126:host:192.168.1.185:host:209.177.158.246SESSION-bcd07bc8e00bd126 β†’ host:192.168.1.185 β†’ host:209.177.158.246
FLOW_TO_HOSTOBSe:to:SESSION-f32643b41a201d5b:host:209.177.158.246SESSION-f32643b41a201d5b β†’ host:209.177.158.246
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-c4d9c40a7fec56be:SESSION-c4d9c40a7fec56beSESSION-c4d9c40a7fec56be β†’ pe:tls:SESSION-c4d9c40a7fec56be
FLOW_QUERIED_DNSOBSe:fd:flow:dc8e0c394478:dns:wpad.mynetworksettings.comflow:dc8e0c394478 β†’ dns:wpad.mynetworksettings.com
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-9c85e6a530e7f20f:host:192.168.1.185:host:192.200.0.112SESSION-9c85e6a530e7f20f β†’ host:192.168.1.185 β†’ host:192.200.0.112
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-441bb1af5ec88ffb:host:192.168.1.185SESSION-441bb1af5ec88ffb β†’ host:192.168.1.185
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-36cd4459caa078a9:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-36cd4459caa078a9 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-b7d90a2138968fa3:host:192.168.1.185SESSION-b7d90a2138968fa3 β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-1835bee014d5b0b3:host:172.17.0.1SESSION-1835bee014d5b0b3 β†’ host:172.17.0.1
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-17e440ba96a7a7b5:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-17e440ba96a7a7b5 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-f8dc5b0051ee4914:host:192.168.1.1SESSION-f8dc5b0051ee4914 β†’ host:192.168.1.1
FLOW_QUERIED_DNSOBSe:fd:flow:0c699e4ab5c4:dns:chatgpt.comflow:0c699e4ab5c4 β†’ dns:chatgpt.com
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-7dbcb4428a9e5e71:host:192.168.1.185:host:209.177.156.94SESSION-7dbcb4428a9e5e71 β†’ host:192.168.1.185 β†’ host:209.177.156.94
FLOW_DST_PORTOBSe:fp:flow:0523b90826b8:port:tcp:51645flow:0523b90826b8 β†’ port:tcp:51645
HOST_GEO_ESTIMATEOBS 60%e:hg:host:151.101.114.172:geo_32.77970_-96.80220host:151.101.114.172 β†’ geo_32.77970_-96.80220
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-05305b96b26cdffd:host:104.18.39.21:host:192.168.1.185SESSION-05305b96b26cdffd β†’ host:104.18.39.21 β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-055fd962754012c2:host:104.208.203.89SESSION-055fd962754012c2 β†’ host:104.208.203.89
FLOW_FROM_HOSTOBSe:from:SESSION-2014bf32e6dab59e:host:192.168.1.185SESSION-2014bf32e6dab59e β†’ host:192.168.1.185
HOST_GEO_ESTIMATEOBS 60%e:hg:host:151.101.112.217:geo_32.77970_-96.80220host:151.101.112.217 β†’ geo_32.77970_-96.80220
HOST_GEO_ESTIMATEOBS 60%e:hg:host:135.234.174.40:geo_38.70950_-78.15390host:135.234.174.40 β†’ geo_38.70950_-78.15390
FLOW_DST_PORTOBSe:fp:flow:e36e1209129d:port:tcp:51049flow:e36e1209129d β†’ port:tcp:51049
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-d146af26ba988e06:SESSION-d146af26ba988e06SESSION-d146af26ba988e06 β†’ pe:tls:SESSION-d146af26ba988e06
FLOW_TO_HOSTOBSe:to:SESSION-e881aa680da5dbf3:host:151.101.112.217SESSION-e881aa680da5dbf3 β†’ host:151.101.112.217
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-e0cdf80170e46e9e:host:192.168.1.185:host:142.250.115.95SESSION-e0cdf80170e46e9e β†’ host:192.168.1.185 β†’ host:142.250.115.95
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-e0cdf80170e46e9e:flow:919c57e90236SESSION-e0cdf80170e46e9e β†’ flow:919c57e90236
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-a019cb392bc23a7a:host:199.165.136.100SESSION-a019cb392bc23a7a β†’ host:199.165.136.100
flow_observed5-aryOBSe:fo:flow:919c57e90236flow:919c57e90236 β†’ host:192.168.1.185 β†’ host:142.250.115.95 β†’ port:udp:443 β†’ svc:https
FLOW_TO_HOSTOBSe:to:SESSION-2681df7af5f78270:host:192.168.1.185SESSION-2681df7af5f78270 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-ea1d23994577309a:host:104.18.22.222SESSION-ea1d23994577309a β†’ host:104.18.22.222
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-7dbcb4428a9e5e71:flow:a42e7b1c53d5SESSION-7dbcb4428a9e5e71 β†’ flow:a42e7b1c53d5
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-fa034e5132aecf5b:SESSION-fa034e5132aecf5bSESSION-fa034e5132aecf5b β†’ pe:tls:SESSION-fa034e5132aecf5b
ASN_IN_ORGOBS 80%e:ao:asn:20940:org:Akamai International B.V.asn:20940 β†’ org:Akamai International B.V.
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-08bfd8721a383a39:host:192.168.1.185SESSION-08bfd8721a383a39 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-8fd6ad39adf47a18:host:104.18.36.216SESSION-8fd6ad39adf47a18 β†’ host:104.18.36.216
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-4cf06bd9f9c07bb4:host:97.178.32.239SESSION-4cf06bd9f9c07bb4 β†’ host:97.178.32.239
flow_observed5-aryOBSe:fo:flow:1cae684ccaf1flow:1cae684ccaf1 β†’ host:192.168.1.185 β†’ host:35.190.80.1 β†’ port:tcp:443 β†’ svc:https
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-21bfec774060aafb:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-21bfec774060aafb β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
flow_observed4-aryOBSe:fo:flow:e36e1209129dflow:e36e1209129d β†’ host:216.24.57.251 β†’ host:192.168.1.185 β†’ port:tcp:51049
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-604f49b2ccac8492:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-604f49b2ccac8492 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-21bfec774060aafb:host:192.168.1.185SESSION-21bfec774060aafb β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:9aa8161296f7:port:tcp:443flow:9aa8161296f7 β†’ port:tcp:443
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-1835bee014d5b0b3:host:172.17.0.1SESSION-1835bee014d5b0b3 β†’ host:172.17.0.1
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-787a71cfd2c6f769:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-787a71cfd2c6f769 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-8fd6ad39adf47a18:host:192.168.1.185SESSION-8fd6ad39adf47a18 β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-05305b96b26cdffd:host:192.168.1.185SESSION-05305b96b26cdffd β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-dabcbf693ac9fbef:host:150.171.28.10SESSION-dabcbf693ac9fbef β†’ host:150.171.28.10
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-e565a4fbf5cff09b:SESSION-e565a4fbf5cff09bSESSION-e565a4fbf5cff09b β†’ pe:tls:SESSION-e565a4fbf5cff09b
SESSION_CONTAINS_EVENTOBSe:pe:pe:syn:SESSION-cbcc97483386b4f3:SESSION-cbcc97483386b4f3SESSION-cbcc97483386b4f3 β†’ pe:syn:SESSION-cbcc97483386b4f3
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-cbcc97483386b4f3:host:192.168.1.185SESSION-cbcc97483386b4f3 β†’ host:192.168.1.185
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-e86e0a049372cc85:flow:d84a13678d67SESSION-e86e0a049372cc85 β†’ flow:d84a13678d67
FLOW_TO_HOSTOBSe:to:SESSION-04dc5a38b6cabcef:host:192.168.1.185SESSION-04dc5a38b6cabcef β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-e66fd8e05921da5d:host:192.168.1.185SESSION-e66fd8e05921da5d β†’ host:192.168.1.185
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-dabcbf693ac9fbef:flow:ab2fda60ec38SESSION-dabcbf693ac9fbef β†’ flow:ab2fda60ec38
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-1f115942b61afe54:host:192.168.1.185:host:192.73.244.245SESSION-1f115942b61afe54 β†’ host:192.168.1.185 β†’ host:192.73.244.245
flow_observed4-aryOBSe:fo:flow:481a8cb33c5bflow:481a8cb33c5b β†’ host:192.168.1.185 β†’ host:192.168.1.1 β†’ port:udp:5351
HOST_IN_ASNOBS 85%e:ha:host:76.76.21.22:asn:16509host:76.76.21.22 β†’ asn:16509
FLOW_TO_HOSTOBSe:to:SESSION-fa034e5132aecf5b:host:13.107.226.57SESSION-fa034e5132aecf5b β†’ host:13.107.226.57
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-858ec5d25a7b6232:host:97.178.32.239SESSION-858ec5d25a7b6232 β†’ host:97.178.32.239
FLOW_DST_PORTOBSe:fp:flow:03d3562fa35f:port:udp:52243flow:03d3562fa35f β†’ port:udp:52243
FLOW_DST_PORTOBSe:fp:flow:a3f08c1df1f5:port:tcp:443flow:a3f08c1df1f5 β†’ port:tcp:443
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-858ec5d25a7b6232:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-858ec5d25a7b6232 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_FROM_HOSTOBSe:from:SESSION-7b2b00e0ceb88c09:host:192.168.1.185SESSION-7b2b00e0ceb88c09 β†’ host:192.168.1.185
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-bcd07bc8e00bd126:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-bcd07bc8e00bd126 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_DST_PORTOBSe:fp:flow:d479ce3b7365:port:tcp:54629flow:d479ce3b7365 β†’ port:tcp:54629
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-4cf06bd9f9c07bb4:host:192.168.1.185SESSION-4cf06bd9f9c07bb4 β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-c8f5f362e7c0c5c8:host:192.168.1.185SESSION-c8f5f362e7c0c5c8 β†’ host:192.168.1.185
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-0e59fb5fe4c720df:flow:00f4e10d6ac7SESSION-0e59fb5fe4c720df β†’ flow:00f4e10d6ac7
FLOW_TO_HOSTOBSe:to:SESSION-5419af02605f5da4:host:97.178.32.239SESSION-5419af02605f5da4 β†’ host:97.178.32.239
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-cbcc97483386b4f3:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-cbcc97483386b4f3 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-9c845bfb2b534b59:SESSION-9c845bfb2b534b59SESSION-9c845bfb2b534b59 β†’ pe:tls:SESSION-9c845bfb2b534b59
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-9dab8edd40d14d9d:flow:f19ee6508782SESSION-9dab8edd40d14d9d β†’ flow:f19ee6508782
FLOW_TO_HOSTOBSe:to:SESSION-06fade4febc8462c:host:104.18.23.222SESSION-06fade4febc8462c β†’ host:104.18.23.222
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-5419af02605f5da4:host:192.168.1.185:host:97.178.32.239SESSION-5419af02605f5da4 β†’ host:192.168.1.185 β†’ host:97.178.32.239
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-716de9787a03c45e:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-716de9787a03c45e β†’ BSG-HORIZ_SCAN-cd2c52661c4b
FLOW_FROM_HOSTOBSe:from:SESSION-741380b5a9a3a6c7:host:172.64.151.22SESSION-741380b5a9a3a6c7 β†’ host:172.64.151.22
FLOW_TO_HOSTOBSe:to:SESSION-86bc6b9e53c222b0:host:23.219.160.5SESSION-86bc6b9e53c222b0 β†’ host:23.219.160.5
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-1065a64ded6cc44c:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-1065a64ded6cc44c β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_DST_PORTOBSe:fp:flow:05b4e5b174c0:port:tcp:54986flow:05b4e5b174c0 β†’ port:tcp:54986
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-e53f703ab7b48a77:host:192.168.1.185:host:199.165.136.100SESSION-e53f703ab7b48a77 β†’ host:192.168.1.185 β†’ host:199.165.136.100
FLOW_TO_HOSTOBSe:to:SESSION-2014bf32e6dab59e:host:151.101.113.140SESSION-2014bf32e6dab59e β†’ host:151.101.113.140
flow_observed5-aryOBSe:fo:flow:f3b81336df74flow:f3b81336df74 β†’ host:192.168.1.185 β†’ host:151.101.112.217 β†’ port:tcp:443 β†’ svc:https
FLOW_TO_HOSTOBSe:to:SESSION-e25097cf84c7b988:host:97.178.32.239SESSION-e25097cf84c7b988 β†’ host:97.178.32.239
FLOW_TO_HOSTOBSe:to:SESSION-200a1edeb5081c1b:host:192.168.1.185SESSION-200a1edeb5081c1b β†’ host:192.168.1.185
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-0e59fb5fe4c720df:SESSION-0e59fb5fe4c720dfSESSION-0e59fb5fe4c720df β†’ pe:tls:SESSION-0e59fb5fe4c720df
flow_observed4-aryOBSe:fo:flow:495f7c8d94fdflow:495f7c8d94fd β†’ host:209.177.156.94 β†’ host:192.168.1.185 β†’ port:tcp:43844
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-65a9e51617aa2712:host:192.168.1.185:host:199.165.136.100SESSION-65a9e51617aa2712 β†’ host:192.168.1.185 β†’ host:199.165.136.100
ASN_IN_ORGOBS 80%e:ao:asn:14618:org:Amazon.com, Inc.asn:14618 β†’ org:Amazon.com, Inc.
FLOW_DST_PORTOBSe:fp:flow:bab9257727f6:port:udp:443flow:bab9257727f6 β†’ port:udp:443
flow_observed5-aryOBSe:fo:flow:7be9da9aa76dflow:7be9da9aa76d β†’ host:192.168.1.185 β†’ host:52.182.143.215 β†’ port:tcp:443 β†’ svc:https
flow_observed4-aryOBSe:fo:flow:4eed5ff51111flow:4eed5ff51111 β†’ host:192.168.1.185 β†’ host:192.168.1.1 β†’ port:tcp:46407
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 95%e:bsg:SESSION-06fade4febc8462c:BSG-DATA_EXFIL-78b438a917b5SESSION-06fade4febc8462c β†’ BSG-DATA_EXFIL-78b438a917b5
flow_observed3-aryOBSe:fo:flow:7395be855a32flow:7395be855a32 β†’ host:97.178.32.239 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-05305b96b26cdffd:host:104.18.39.21SESSION-05305b96b26cdffd β†’ host:104.18.39.21
FLOW_TLS_SNIOBSe:fs:flow:7be9da9aa76d:tls_sni:browser.events.data.microsoft.comflow:7be9da9aa76d β†’ tls_sni:browser.events.data.microsoft.com
flow_observed5-aryOBSe:fo:flow:0c699e4ab5c4flow:0c699e4ab5c4 β†’ host:192.168.1.185 β†’ host:192.168.1.1 β†’ port:udp:53 β†’ svc:dns
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-10cf97843d85c279:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-10cf97843d85c279 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-2014bf32e6dab59e:SESSION-2014bf32e6dab59eSESSION-2014bf32e6dab59e β†’ pe:tls:SESSION-2014bf32e6dab59e
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-d7f6ed06cf3ab18b:flow:df281449ac19SESSION-d7f6ed06cf3ab18b β†’ flow:df281449ac19
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-7b2b00e0ceb88c09:flow:4ac806f4d834SESSION-7b2b00e0ceb88c09 β†’ flow:4ac806f4d834
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-08bfd8721a383a39:flow:dc8e0c394478SESSION-08bfd8721a383a39 β†’ flow:dc8e0c394478
FLOW_TO_HOSTOBSe:to:SESSION-10cf97843d85c279:host:209.177.156.94SESSION-10cf97843d85c279 β†’ host:209.177.156.94
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-c4d9c40a7fec56be:host:192.168.1.185:host:135.234.174.40SESSION-c4d9c40a7fec56be β†’ host:192.168.1.185 β†’ host:135.234.174.40
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-348feef1c6ca6285:host:192.168.1.185SESSION-348feef1c6ca6285 β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-36cd4459caa078a9:host:192.168.1.185:host:135.234.174.40SESSION-36cd4459caa078a9 β†’ host:192.168.1.185 β†’ host:135.234.174.40
flow_observed5-aryOBSe:fo:flow:21a678dc75deflow:21a678dc75de β†’ host:192.168.1.185 β†’ host:199.165.136.100 β†’ port:tcp:443 β†’ svc:https
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-e881aa680da5dbf3:host:192.168.1.185:host:151.101.112.217SESSION-e881aa680da5dbf3 β†’ host:192.168.1.185 β†’ host:151.101.112.217
flow_observed4-aryOBSe:fo:flow:00f4e10d6ac7flow:00f4e10d6ac7 β†’ host:209.177.156.94 β†’ host:192.168.1.185 β†’ port:tcp:43844
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-c8f5f362e7c0c5c8:host:216.24.57.251:host:192.168.1.185SESSION-c8f5f362e7c0c5c8 β†’ host:216.24.57.251 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-858ec5d25a7b6232:host:192.168.1.185SESSION-858ec5d25a7b6232 β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:137f07aaadb4:port:udp:41641flow:137f07aaadb4 β†’ port:udp:41641
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-08bfd8721a383a39:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-08bfd8721a383a39 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-99947e3aab494326:host:192.200.0.112SESSION-99947e3aab494326 β†’ host:192.200.0.112
PORT_IMPLIED_SERVICEIMP 70%e:ps:port:udp:53:svc:dnsport:udp:53 β†’ svc:dns
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-1ea83345da6e2df0:host:192.168.1.165SESSION-1ea83345da6e2df0 β†’ host:192.168.1.165
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-0e59fb5fe4c720df:host:209.177.156.94:host:192.168.1.185SESSION-0e59fb5fe4c720df β†’ host:209.177.156.94 β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:46f60ddc23a2:port:tcp:46407flow:46f60ddc23a2 β†’ port:tcp:46407
FLOW_TO_HOSTOBSe:to:SESSION-8394aca80c2a0790:host:52.182.143.215SESSION-8394aca80c2a0790 β†’ host:52.182.143.215
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-716de9787a03c45e:flow:3d20532e84edSESSION-716de9787a03c45e β†’ flow:3d20532e84ed
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e0cdf80170e46e9e:host:142.250.115.95SESSION-e0cdf80170e46e9e β†’ host:142.250.115.95
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-dabcbf693ac9fbef:host:192.168.1.185:host:150.171.28.10SESSION-dabcbf693ac9fbef β†’ host:192.168.1.185 β†’ host:150.171.28.10
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-05305b96b26cdffd:host:192.168.1.185SESSION-05305b96b26cdffd β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:51a92af49050:port:tcp:443flow:51a92af49050 β†’ port:tcp:443
FLOW_TO_HOSTOBSe:to:SESSION-e0cdf80170e46e9e:host:142.250.115.95SESSION-e0cdf80170e46e9e β†’ host:142.250.115.95
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-934baa2aae663ceb:host:192.168.1.185SESSION-934baa2aae663ceb β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-36cd4459caa078a9:host:192.168.1.185SESSION-36cd4459caa078a9 β†’ host:192.168.1.185
HOST_GEO_ESTIMATEOBS 60%e:hg:host:104.208.203.89:geo_36.66940_-78.38770host:104.208.203.89 β†’ geo_36.66940_-78.38770
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 95%e:bsg:SESSION-cbcc97483386b4f3:BSG-DATA_EXFIL-78b438a917b5SESSION-cbcc97483386b4f3 β†’ BSG-DATA_EXFIL-78b438a917b5
flow_observed4-aryOBSe:fo:flow:c65476284ea0flow:c65476284ea0 β†’ host:162.159.128.61 β†’ host:192.168.1.185 β†’ port:tcp:61509
FLOW_FROM_HOSTOBSe:from:SESSION-b7d90a2138968fa3:host:209.177.156.94SESSION-b7d90a2138968fa3 β†’ host:209.177.156.94
HOST_IN_ASNOBS 85%e:ha:host:151.101.114.172:asn:54113host:151.101.114.172 β†’ asn:54113
FLOW_FROM_HOSTOBSe:from:SESSION-0e59fb5fe4c720df:host:209.177.156.94SESSION-0e59fb5fe4c720df β†’ host:209.177.156.94
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-65e185b6eab54d6a:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-65e185b6eab54d6a β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
FLOW_TO_HOSTOBSe:to:SESSION-c4d9c40a7fec56be:host:135.234.174.40SESSION-c4d9c40a7fec56be β†’ host:135.234.174.40
FLOW_DST_PORTOBSe:fp:flow:0380e0cd29dc:port:tcp:52640flow:0380e0cd29dc β†’ port:tcp:52640
FLOW_FROM_HOSTOBSe:from:SESSION-441bb1af5ec88ffb:host:192.168.1.185SESSION-441bb1af5ec88ffb β†’ host:192.168.1.185
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-8c7ddbb6fe26a9a9:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-8c7ddbb6fe26a9a9 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
HOST_GEO_ESTIMATEOBS 60%e:hg:host:52.182.143.215:geo_41.60150_-93.61270host:52.182.143.215 β†’ geo_41.60150_-93.61270
FLOW_DST_PORTOBSe:fp:flow:9d482c927ad5:port:tcp:443flow:9d482c927ad5 β†’ port:tcp:443
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 95%e:bsg:SESSION-8394aca80c2a0790:BSG-DATA_EXFIL-78b438a917b5SESSION-8394aca80c2a0790 β†’ BSG-DATA_EXFIL-78b438a917b5
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-c8f5f362e7c0c5c8:SESSION-c8f5f362e7c0c5c8SESSION-c8f5f362e7c0c5c8 β†’ pe:tls:SESSION-c8f5f362e7c0c5c8
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-68666b77cce29d40:host:192.168.1.185:host:192.168.1.1SESSION-68666b77cce29d40 β†’ host:192.168.1.185 β†’ host:192.168.1.1
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-36cd4459caa078a9:SESSION-36cd4459caa078a9SESSION-36cd4459caa078a9 β†’ pe:tls:SESSION-36cd4459caa078a9
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-e0cdf80170e46e9e:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-e0cdf80170e46e9e β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-184b3698d564c9c7:flow:a25fcb74f721SESSION-184b3698d564c9c7 β†’ flow:a25fcb74f721
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-68666b77cce29d40:host:192.168.1.185SESSION-68666b77cce29d40 β†’ host:192.168.1.185
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-716de9787a03c45e:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-716de9787a03c45e β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-1835bee014d5b0b3:host:192.168.1.185:host:172.17.0.1SESSION-1835bee014d5b0b3 β†’ host:192.168.1.185 β†’ host:172.17.0.1
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-441bb1af5ec88ffb:SESSION-441bb1af5ec88ffbSESSION-441bb1af5ec88ffb β†’ pe:tls:SESSION-441bb1af5ec88ffb
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-e25097cf84c7b988:flow:682d5368c69eSESSION-e25097cf84c7b988 β†’ flow:682d5368c69e
HOST_GEO_ESTIMATEOBS 60%e:hg:host:20.62.59.32:geo_36.66940_-78.38770host:20.62.59.32 β†’ geo_36.66940_-78.38770
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-dabcbf693ac9fbef:SESSION-dabcbf693ac9fbefSESSION-dabcbf693ac9fbef β†’ pe:tls:SESSION-dabcbf693ac9fbef
FLOW_TO_HOSTOBSe:to:SESSION-b7338ba843b2dafa:host:192.73.248.83SESSION-b7338ba843b2dafa β†’ host:192.73.248.83
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-86bc6b9e53c222b0:host:192.168.1.185:host:23.219.160.5SESSION-86bc6b9e53c222b0 β†’ host:192.168.1.185 β†’ host:23.219.160.5
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-8fd6ad39adf47a18:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-8fd6ad39adf47a18 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-ce6603a48a5c4c37:flow:bab9257727f6SESSION-ce6603a48a5c4c37 β†’ flow:bab9257727f6
HOST_IN_ASNOBS 85%e:ha:host:142.250.113.95:asn:15169host:142.250.113.95 β†’ asn:15169
FLOW_FROM_HOSTOBSe:from:SESSION-e6729d0ebc579395:host:192.168.1.185SESSION-e6729d0ebc579395 β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-7bf53771cd98ec17:host:192.168.1.185:host:192.168.1.1SESSION-7bf53771cd98ec17 β†’ host:192.168.1.185 β†’ host:192.168.1.1
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-f8dc5b0051ee4914:host:192.168.1.185SESSION-f8dc5b0051ee4914 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-055fd962754012c2:host:192.168.1.185SESSION-055fd962754012c2 β†’ host:192.168.1.185
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-68666b77cce29d40:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-68666b77cce29d40 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-348feef1c6ca6285:host:151.101.113.140SESSION-348feef1c6ca6285 β†’ host:151.101.113.140
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-d146af26ba988e06:host:192.168.1.185:host:104.18.32.47SESSION-d146af26ba988e06 β†’ host:192.168.1.185 β†’ host:104.18.32.47
flow_observed5-aryOBSe:fo:flow:51a92af49050flow:51a92af49050 β†’ host:192.168.1.185 β†’ host:76.76.21.22 β†’ port:tcp:443 β†’ svc:https
FLOW_DST_PORTOBSe:fp:flow:1cae684ccaf1:port:tcp:443flow:1cae684ccaf1 β†’ port:tcp:443
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-04dc5a38b6cabcef:host:192.168.1.185SESSION-04dc5a38b6cabcef β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-f32643b41a201d5b:host:192.168.1.185SESSION-f32643b41a201d5b β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-2681df7af5f78270:host:97.178.32.239:host:192.168.1.185SESSION-2681df7af5f78270 β†’ host:97.178.32.239 β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-06fade4febc8462c:host:104.18.23.222SESSION-06fade4febc8462c β†’ host:104.18.23.222
FLOW_DST_PORTOBSe:fp:flow:027ad06c15d5:port:tcp:55880flow:027ad06c15d5 β†’ port:tcp:55880
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-e881aa680da5dbf3:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-e881aa680da5dbf3 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
FLOW_TO_HOSTOBSe:to:SESSION-bc4350b5c6d66f3f:host:34.111.31.13SESSION-bc4350b5c6d66f3f β†’ host:34.111.31.13
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-81e5b5be161de125:host:151.101.114.172SESSION-81e5b5be161de125 β†’ host:151.101.114.172
SESSION_CONTAINS_EVENTOBSe:pe:pe:syn:SESSION-81e5b5be161de125:SESSION-81e5b5be161de125SESSION-81e5b5be161de125 β†’ pe:syn:SESSION-81e5b5be161de125
FLOW_TO_HOSTOBSe:to:SESSION-e6ad21d692182871:host:199.165.136.100SESSION-e6ad21d692182871 β†’ host:199.165.136.100
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-99947e3aab494326:flow:0523b90826b8SESSION-99947e3aab494326 β†’ flow:0523b90826b8
FLOW_FROM_HOSTOBSe:from:SESSION-b7338ba843b2dafa:host:192.168.1.185SESSION-b7338ba843b2dafa β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e86e0a049372cc85:host:192.168.1.185SESSION-e86e0a049372cc85 β†’ host:192.168.1.185
HOST_IN_ASNOBS 85%e:ha:host:23.213.232.172:asn:20940host:23.213.232.172 β†’ asn:20940
HOST_IN_ASNOBS 85%e:ha:host:142.250.115.95:asn:15169host:142.250.115.95 β†’ asn:15169
HOST_IN_ASNOBS 85%e:ha:host:167.235.217.196:asn:24940host:167.235.217.196 β†’ asn:24940
FLOW_DST_PORTOBSe:fp:flow:a42e7b1c53d5:port:udp:3478flow:a42e7b1c53d5 β†’ port:udp:3478
FLOW_QUERIED_DNSOBSe:fd:flow:660ca437efa1:dns:copilot.microsoft.comflow:660ca437efa1 β†’ dns:copilot.microsoft.com
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-f32643b41a201d5b:flow:dd3dd13e1b60SESSION-f32643b41a201d5b β†’ flow:dd3dd13e1b60
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-e66fd8e05921da5d:flow:26faad66f81eSESSION-e66fd8e05921da5d β†’ flow:26faad66f81e
FLOW_DST_PORTOBSe:fp:flow:300bb0be41cf:port:tcp:443flow:300bb0be41cf β†’ port:tcp:443
FLOW_FROM_HOSTOBSe:from:SESSION-9c845bfb2b534b59:host:192.168.1.185SESSION-9c845bfb2b534b59 β†’ host:192.168.1.185
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-d7f6ed06cf3ab18b:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-d7f6ed06cf3ab18b β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-d146af26ba988e06:flow:f25397a8d5d5SESSION-d146af26ba988e06 β†’ flow:f25397a8d5d5
FLOW_DST_PORTOBSe:fp:flow:481a8cb33c5b:port:udp:5351flow:481a8cb33c5b β†’ port:udp:5351
FLOW_DST_PORTOBSe:fp:flow:7be9da9aa76d:port:tcp:443flow:7be9da9aa76d β†’ port:tcp:443
HOST_IN_ASNOBS 85%e:ha:host:52.182.143.215:asn:8075host:52.182.143.215 β†’ asn:8075
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-65a9e51617aa2712:SESSION-65a9e51617aa2712SESSION-65a9e51617aa2712 β†’ pe:tls:SESSION-65a9e51617aa2712
FLOW_TO_HOSTOBSe:to:SESSION-e6729d0ebc579395:host:97.178.32.239SESSION-e6729d0ebc579395 β†’ host:97.178.32.239
FLOW_TO_HOSTOBSe:to:SESSION-7dbcb4428a9e5e71:host:209.177.156.94SESSION-7dbcb4428a9e5e71 β†’ host:209.177.156.94
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-0e59fb5fe4c720df:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-0e59fb5fe4c720df β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
flow_observed5-aryOBSe:fo:flow:779733f74cebflow:779733f74ceb β†’ host:192.168.1.185 β†’ host:104.208.203.89 β†’ port:tcp:443 β†’ svc:https
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-fa034e5132aecf5b:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-fa034e5132aecf5b β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-04dc5a38b6cabcef:host:167.235.217.196SESSION-04dc5a38b6cabcef β†’ host:167.235.217.196
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-423d6f8fa2a9f7bc:host:23.213.232.172SESSION-423d6f8fa2a9f7bc β†’ host:23.213.232.172
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-9b68d4601d0ccd30:flow:f5abaef54664SESSION-9b68d4601d0ccd30 β†’ flow:f5abaef54664
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-7bf53771cd98ec17:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-7bf53771cd98ec17 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-1835bee014d5b0b3:host:192.168.1.185SESSION-1835bee014d5b0b3 β†’ host:192.168.1.185
FLOW_DST_PORTOBSe:fp:flow:1fbee9feb06d:port:tcp:51146flow:1fbee9feb06d β†’ port:tcp:51146
HOST_IN_ASNOBS 85%e:ha:host:151.101.113.140:asn:54113host:151.101.113.140 β†’ asn:54113
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-934baa2aae663ceb:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-934baa2aae663ceb β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-5673cdc8e15ecc28:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-5673cdc8e15ecc28 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-65a9e51617aa2712:flow:21a678dc75deSESSION-65a9e51617aa2712 β†’ flow:21a678dc75de
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-e66fd8e05921da5d:host:192.168.1.185:host:172.18.0.1SESSION-e66fd8e05921da5d β†’ host:192.168.1.185 β†’ host:172.18.0.1
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-9c85e6a530e7f20f:SESSION-9c85e6a530e7f20fSESSION-9c85e6a530e7f20f β†’ pe:tls:SESSION-9c85e6a530e7f20f
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-441bb1af5ec88ffb:flow:51a92af49050SESSION-441bb1af5ec88ffb β†’ flow:51a92af49050
FLOW_TO_HOSTOBSe:to:SESSION-d146af26ba988e06:host:104.18.32.47SESSION-d146af26ba988e06 β†’ host:104.18.32.47
SESSION_CONTAINS_EVENTOBSe:pe:pe:dns:SESSION-58f9cafe500f64ad:SESSION-58f9cafe500f64adSESSION-58f9cafe500f64ad β†’ pe:dns:SESSION-58f9cafe500f64ad
flow_observed4-aryOBSe:fo:flow:fdf049da8b14flow:fdf049da8b14 β†’ host:192.168.1.185 β†’ host:209.177.156.94 β†’ port:udp:3478
FLOW_FROM_HOSTOBSe:from:SESSION-06fade4febc8462c:host:192.168.1.185SESSION-06fade4febc8462c β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-d7f6ed06cf3ab18b:host:192.168.1.185SESSION-d7f6ed06cf3ab18b β†’ host:192.168.1.185
FLOW_TO_HOSTOBSe:to:SESSION-65a9e51617aa2712:host:199.165.136.100SESSION-65a9e51617aa2712 β†’ host:199.165.136.100
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-bc4350b5c6d66f3f:host:192.168.1.185:host:34.111.31.13SESSION-bc4350b5c6d66f3f β†’ host:192.168.1.185 β†’ host:34.111.31.13
FLOW_FROM_HOSTOBSe:from:SESSION-e25097cf84c7b988:host:192.168.1.185SESSION-e25097cf84c7b988 β†’ host:192.168.1.185
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-58f9cafe500f64ad:host:192.168.1.185:host:192.168.1.1SESSION-58f9cafe500f64ad β†’ host:192.168.1.185 β†’ host:192.168.1.1
FLOW_TO_HOSTOBSe:to:SESSION-9c85e6a530e7f20f:host:192.200.0.112SESSION-9c85e6a530e7f20f β†’ host:192.200.0.112
FLOW_FROM_HOSTOBSe:from:SESSION-04dc5a38b6cabcef:host:167.235.217.196SESSION-04dc5a38b6cabcef β†’ host:167.235.217.196
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-58f9cafe500f64ad:host:192.168.1.185SESSION-58f9cafe500f64ad β†’ host:192.168.1.185
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-1f115942b61afe54:host:192.73.244.245SESSION-1f115942b61afe54 β†’ host:192.73.244.245
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-fa034e5132aecf5b:host:13.107.226.57SESSION-fa034e5132aecf5b β†’ host:13.107.226.57
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-ce6603a48a5c4c37:host:23.219.160.5SESSION-ce6603a48a5c4c37 β†’ host:23.219.160.5
HOST_IN_ASNOBS 85%e:ha:host:192.73.243.135:asn:36236host:192.73.243.135 β†’ asn:36236
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 95%e:bsg:SESSION-b7338ba843b2dafa:BSG-DATA_EXFIL-78b438a917b5SESSION-b7338ba843b2dafa β†’ BSG-DATA_EXFIL-78b438a917b5
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-604f49b2ccac8492:host:192.168.1.185SESSION-604f49b2ccac8492 β†’ host:192.168.1.185
FLOW_FROM_HOSTOBSe:from:SESSION-1f115942b61afe54:host:192.168.1.185SESSION-1f115942b61afe54 β†’ host:192.168.1.185
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-8fd6ad39adf47a18:flow:027ad06c15d5SESSION-8fd6ad39adf47a18 β†’ flow:027ad06c15d5
HOST_GEO_ESTIMATEOBS 60%e:hg:host:209.177.158.246:geo_41.88350_-87.63050host:209.177.158.246 β†’ geo_41.88350_-87.63050
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-2681df7af5f78270:host:97.178.32.239SESSION-2681df7af5f78270 β†’ host:97.178.32.239
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-e86e0a049372cc85:host:142.250.113.95SESSION-e86e0a049372cc85 β†’ host:142.250.113.95
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-741380b5a9a3a6c7:flow:ef26bc2c964dSESSION-741380b5a9a3a6c7 β†’ flow:ef26bc2c964d
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-d7f6ed06cf3ab18b:host:97.178.32.239SESSION-d7f6ed06cf3ab18b β†’ host:97.178.32.239
FLOW_DST_PORTOBSe:fp:flow:682d5368c69e:port:udp:1050flow:682d5368c69e β†’ port:udp:1050
FLOW_FROM_HOSTOBSe:from:SESSION-d7f6ed06cf3ab18b:host:97.178.32.239SESSION-d7f6ed06cf3ab18b β†’ host:97.178.32.239
flow_observed4-aryOBSe:fo:flow:f19ee6508782flow:f19ee6508782 β†’ host:104.18.39.21 β†’ host:192.168.1.185 β†’ port:tcp:58457
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 90%e:bsg:SESSION-348feef1c6ca6285:BSG-BEACON-3fa1dca5627cSESSION-348feef1c6ca6285 β†’ BSG-BEACON-3fa1dca5627c
flow_observed5-aryOBSe:fo:flow:6fe67514daf4flow:6fe67514daf4 β†’ host:192.168.1.185 β†’ host:192.73.248.83 β†’ port:tcp:443 β†’ svc:https
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-1ea83345da6e2df0:flow:d658b18ff560SESSION-1ea83345da6e2df0 β†’ flow:d658b18ff560
flow_observed5-aryOBSe:fo:flow:007f4ea11c64flow:007f4ea11c64 β†’ host:192.168.1.185 β†’ host:135.234.174.40 β†’ port:tcp:443 β†’ svc:https
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-de97a19f0937505c:flow:1fbee9feb06dSESSION-de97a19f0937505c β†’ flow:1fbee9feb06d
SESSION_CONTAINS_EVENTOBSe:pe:pe:tls:SESSION-ea1d23994577309a:SESSION-ea1d23994577309aSESSION-ea1d23994577309a β†’ pe:tls:SESSION-ea1d23994577309a
SESSION_MEMBER_OF_BEHAVIOR_GROUPOBS 80%e:bsg:SESSION-e86e0a049372cc85:BSG-HORIZ_SCAN-cd2c52661c4bSESSION-e86e0a049372cc85 β†’ BSG-HORIZ_SCAN-cd2c52661c4b
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-22420a928847cfad:flow:481a8cb33c5bSESSION-22420a928847cfad β†’ flow:481a8cb33c5b
FLOW_TO_HOSTOBSe:to:SESSION-cbcc97483386b4f3:host:104.18.32.47SESSION-cbcc97483386b4f3 β†’ host:104.18.32.47
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-055fd962754012c2:host:104.208.203.89SESSION-055fd962754012c2 β†’ host:104.208.203.89
SESSION_DERIVED_FROM_PCAPOBSe:derived:SESSION-b7d90a2138968fa3:PCAP:cap_05182026_430pmCST:aee251eecdd8SESSION-b7d90a2138968fa3 β†’ PCAP:cap_05182026_430pmCST:aee251eecdd8
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-329be171c0b80b92:host:172.29.16.1SESSION-329be171c0b80b92 β†’ host:172.29.16.1
flow_observed5-aryOBSe:fo:flow:f25397a8d5d5flow:f25397a8d5d5 β†’ host:192.168.1.185 β†’ host:104.18.32.47 β†’ port:tcp:443 β†’ svc:https
FLOW_TO_HOSTOBSe:to:SESSION-65e185b6eab54d6a:host:192.168.1.1SESSION-65e185b6eab54d6a β†’ host:192.168.1.1
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-741380b5a9a3a6c7:host:172.64.151.22SESSION-741380b5a9a3a6c7 β†’ host:172.64.151.22
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-c4d9c40a7fec56be:flow:007f4ea11c64SESSION-c4d9c40a7fec56be β†’ flow:007f4ea11c64
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-1ea83345da6e2df0:host:224.0.0.22SESSION-1ea83345da6e2df0 β†’ host:224.0.0.22
SESSION_OBSERVED_FLOWOBSe:sof:SESSION-68666b77cce29d40:flow:0c699e4ab5c4SESSION-68666b77cce29d40 β†’ flow:0c699e4ab5c4
flow_observed5-aryOBSe:fo:flow:dc8e0c394478flow:dc8e0c394478 β†’ host:192.168.1.185 β†’ host:192.168.1.1 β†’ port:udp:53 β†’ svc:dns
SESSION_BETWEEN_HOSTS3-aryOBSe:sbh:SESSION-08bfd8721a383a39:host:192.168.1.185:host:192.168.1.1SESSION-08bfd8721a383a39 β†’ host:192.168.1.185 β†’ host:192.168.1.1
HOST_IN_ASNOBS 85%e:ha:host:34.111.31.13:asn:396982host:34.111.31.13 β†’ asn:396982
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-21bfec774060aafb:host:192.168.1.1SESSION-21bfec774060aafb β†’ host:192.168.1.1
SESSION_OBSERVED_HOSTOBSe:soh:SESSION-83d0b20751c23f69:host:192.168.1.185SESSION-83d0b20751c23f69 β†’ host:192.168.1.185