Nodes (549)
Edges (1702)
| Kind | Label | ID |
|---|---|---|
| session | SESSION-88cb0f0db49ee3f8 | SESSION-88cb0f0db49ee3f8 |
| session | SESSION-52a9a40458bd9752 | SESSION-52a9a40458bd9752 |
| flow | flow:72c6eeec3d6a | flow:72c6eeec3d6a |
| protocol_event | pe:syn:SESSION-f1084471ac1c8494 | pe:syn:SESSION-f1084471ac1c8 |
| session | SESSION-47b317e81372877c | SESSION-47b317e81372877c |
| flow | flow:8079718a486a | flow:8079718a486a |
| flow | flow:3d32b701d291 | flow:3d32b701d291 |
| port_hub | 44321 | port:tcp:44321 |
| port_hub | 53893 | port:tcp:53893 |
| flow | flow:cf292b6fd57a | flow:cf292b6fd57a |
| host | 127.0.0.1 | host:127.0.0.1 |
| host | 100.100.100.100 | host:100.100.100.100 |
| protocol_event | pe:dns:SESSION-dd725f94abd254e2 | pe:dns:SESSION-dd725f94abd25 |
| service | http-alt | svc:http-alt |
| port_hub | 3306 | port:tcp:3306 |
| flow | flow:620a75ddcce9 | flow:620a75ddcce9 |
| session | SESSION-273cd57b7353458c | SESSION-273cd57b7353458c |
| flow | flow:a46e00cfd24b | flow:a46e00cfd24b |
| flow | flow:fbaff133bca3 | flow:fbaff133bca3 |
| protocol_event | pe:syn:SESSION-ecd5913739d83929 | pe:syn:SESSION-ecd5913739d83 |
| session | SESSION-eade9b324c3f2d97 | SESSION-eade9b324c3f2d97 |
| protocol_event | pe:syn:SESSION-50f7e5069cfb33f9 | pe:syn:SESSION-50f7e5069cfb3 |
| session | SESSION-3a15d20dea9f822c | SESSION-3a15d20dea9f822c |
| protocol_event | pe:syn:SESSION-af4d92b3b5686b54 | pe:syn:SESSION-af4d92b3b5686 |
| session | SESSION-e1becb6cb0fa28cc | SESSION-e1becb6cb0fa28cc |
| protocol_event | pe:syn:SESSION-2f4b9580a4a1affc | pe:syn:SESSION-2f4b9580a4a1a |
| protocol_event | pe:syn:SESSION-750d6db7eef625c0 | pe:syn:SESSION-750d6db7eef62 |
| protocol_event | pe:syn:SESSION-e839b37af81133b6 | pe:syn:SESSION-e839b37af8113 |
| session | SESSION-a4fad28b257d25e0 | SESSION-a4fad28b257d25e0 |
| session | SESSION-aa99cce81b7c8c65 | SESSION-aa99cce81b7c8c65 |
| protocol_event | pe:syn:SESSION-b2a96b6bce11d947 | pe:syn:SESSION-b2a96b6bce11d |
| flow | flow:f551d2e7ab94 | flow:f551d2e7ab94 |
| flow | flow:3e019d07acd1 | flow:3e019d07acd1 |
| session | SESSION-cbe987946fcf62e6 | SESSION-cbe987946fcf62e6 |
| session | SESSION-6ab45024e97e63c6 | SESSION-6ab45024e97e63c6 |
| flow | flow:132be34f6f05 | flow:132be34f6f05 |
| port_hub | 11434 | port:tcp:11434 |
| flow | flow:54a30900cafc | flow:54a30900cafc |
| session | SESSION-e0850aee2c012568 | SESSION-e0850aee2c012568 |
| session | SESSION-c57153cd232e3fdc | SESSION-c57153cd232e3fdc |
| flow | flow:0376420660f8 | flow:0376420660f8 |
| flow | flow:f42a8bf31025 | flow:f42a8bf31025 |
| protocol_event | pe:syn:SESSION-14a0eb6f1896314a | pe:syn:SESSION-14a0eb6f18963 |
| protocol_event | pe:rst:SESSION-effec288f6ec645b | pe:rst:SESSION-effec288f6ec6 |
| protocol_event | pe:syn:SESSION-f3139c2f111954b1 | pe:syn:SESSION-f3139c2f11195 |
| session | SESSION-d477766246cf20f1 | SESSION-d477766246cf20f1 |
| protocol_event | pe:syn:SESSION-effec288f6ec645b | pe:syn:SESSION-effec288f6ec6 |
| session | SESSION-d179889405ae872b | SESSION-d179889405ae872b |
| service | dns | svc:dns |
| protocol_event | pe:syn:SESSION-e0cd994b6ff4b517 | pe:syn:SESSION-e0cd994b6ff4b |
| host | 10.255.255.254 | host:10.255.255.254 |
| flow | flow:3eb65c45cc4a | flow:3eb65c45cc4a |
| session | SESSION-e56034d531876f8e | SESSION-e56034d531876f8e |
| flow | flow:ba2f038de90e | flow:ba2f038de90e |
| flow | flow:27debc11da09 | flow:27debc11da09 |
| protocol_event | pe:syn:SESSION-f2b2f468777f0928 | pe:syn:SESSION-f2b2f468777f0 |
| flow | flow:50f60928c91b | flow:50f60928c91b |
| protocol_event | pe:syn:SESSION-d2eae1f56fe97771 | pe:syn:SESSION-d2eae1f56fe97 |
| session | SESSION-a189b0f57a23c78d | SESSION-a189b0f57a23c78d |
| flow | flow:c78ece3eba58 | flow:c78ece3eba58 |
| flow | flow:dd3d723d3c8b | flow:dd3d723d3c8b |
| flow | flow:ed036b810231 | flow:ed036b810231 |
| session | SESSION-5fba0156cbdcef6a | SESSION-5fba0156cbdcef6a |
| protocol_event | pe:dns:SESSION-e1becb6cb0fa28cc | pe:dns:SESSION-e1becb6cb0fa2 |
| session | SESSION-ded2b3c63390f11d | SESSION-ded2b3c63390f11d |
| protocol_event | pe:syn:SESSION-feb55551c2670490 | pe:syn:SESSION-feb55551c2670 |
| flow | flow:039ef4ad8dd3 | flow:039ef4ad8dd3 |
| flow | flow:cdb0de3f9d6d | flow:cdb0de3f9d6d |
| port_hub | 53622 | port:tcp:53622 |
| flow | flow:0aa0daac822f | flow:0aa0daac822f |
| session | SESSION-21c44b7c852f5d48 | SESSION-21c44b7c852f5d48 |
| flow | flow:6d0ae7f33c5a | flow:6d0ae7f33c5a |
| session | SESSION-8d137995a1d20bf6 | SESSION-8d137995a1d20bf6 |
| protocol_event | pe:syn:SESSION-c8b0c60227867fbf | pe:syn:SESSION-c8b0c60227867 |
| session | SESSION-fa07559c364104a9 | SESSION-fa07559c364104a9 |
| session | SESSION-48c7de3383040629 | SESSION-48c7de3383040629 |
| protocol_event | pe:syn:SESSION-907d871bde93803f | pe:syn:SESSION-907d871bde938 |
| session | SESSION-5b564b5673a8375f | SESSION-5b564b5673a8375f |
| session | SESSION-e10fa25545d53b19 | SESSION-e10fa25545d53b19 |
| port_hub | 53885 | port:tcp:53885 |
| session | SESSION-e5386642f6de2d8e | SESSION-e5386642f6de2d8e |
| flow | flow:cc07c92af3ed | flow:cc07c92af3ed |
| flow | flow:2019351989a4 | flow:2019351989a4 |
| session | SESSION-af0e418207af37d1 | SESSION-af0e418207af37d1 |
| flow | flow:f0ab208e5767 | flow:f0ab208e5767 |
| session | SESSION-c1fc784f6ad7543f | SESSION-c1fc784f6ad7543f |
| session | SESSION-e91c7b3d95a2a341 | SESSION-e91c7b3d95a2a341 |
| behavior_group | BSG-BEACON-f06cc4040ae0 | BSG-BEACON-f06cc4040ae0 |
| org | Amazon.com, Inc. | org:Amazon.com, Inc. |
| session | SESSION-f0ba11b9cd11605f | SESSION-f0ba11b9cd11605f |
| protocol_event | pe:syn:SESSION-fe6c2a163855dc38 | pe:syn:SESSION-fe6c2a163855d |
| port_hub | 44120 | port:tcp:44120 |
| session | SESSION-859db4a81791fe6d | SESSION-859db4a81791fe6d |
| flow | flow:feeae5eb4ff2 | flow:feeae5eb4ff2 |
| protocol_event | pe:syn:SESSION-f0cac35db2fab18a | pe:syn:SESSION-f0cac35db2fab |
| protocol_event | pe:rst:SESSION-f0ba11b9cd11605f | pe:rst:SESSION-f0ba11b9cd116 |
| session | SESSION-f66df5d47c787717 | SESSION-f66df5d47c787717 |
| session | SESSION-8ec1e101886212aa | SESSION-8ec1e101886212aa |
| session | SESSION-3be06d33bb623daa | SESSION-3be06d33bb623daa |
| protocol_event | pe:syn:SESSION-c97958f2086a2a04 | pe:syn:SESSION-c97958f2086a2 |
| port_hub | 59961 | port:tcp:59961 |
| protocol_event | pe:syn:SESSION-707f3d5cd8febf7c | pe:syn:SESSION-707f3d5cd8feb |
| protocol_event | pe:syn:SESSION-8266fc4f0c69a273 | pe:syn:SESSION-8266fc4f0c69a |
| protocol_event | pe:syn:SESSION-0c892504383e1ab6 | pe:syn:SESSION-0c892504383e1 |
| flow | flow:8986709b022a | flow:8986709b022a |
| flow | flow:e30107e849ed | flow:e30107e849ed |
| protocol_event | pe:syn:SESSION-5ea5580aef61d4b1 | pe:syn:SESSION-5ea5580aef61d |
| flow | flow:c8d28b53b003 | flow:c8d28b53b003 |
| flow | flow:babf8c64afcb | flow:babf8c64afcb |
| flow | flow:72455960b0ed | flow:72455960b0ed |
| session | SESSION-df4461d50dc4a9e3 | SESSION-df4461d50dc4a9e3 |
| flow | flow:c2b263c87c2b | flow:c2b263c87c2b |
| port_hub | 6456 | port:tcp:6456 |
| session | SESSION-dec2cc51b7fa8da3 | SESSION-dec2cc51b7fa8da3 |
| protocol_event | pe:tls:SESSION-3f0ef7f428c88827 | pe:tls:SESSION-3f0ef7f428c88 |
| session | SESSION-ef4e1f0381264bb8 | SESSION-ef4e1f0381264bb8 |
| flow | flow:44c75a6a75af | flow:44c75a6a75af |
| flow | flow:1856bec58d51 | flow:1856bec58d51 |
| flow | flow:57246ba1525b | flow:57246ba1525b |
| session | SESSION-b8aaaeead9846ee4 | SESSION-b8aaaeead9846ee4 |
| protocol_event | pe:dns:SESSION-48c7de3383040629 | pe:dns:SESSION-48c7de3383040 |
| flow | flow:beb569ff9b4f | flow:beb569ff9b4f |
| flow | flow:cd7804875940 | flow:cd7804875940 |
| flow | flow:fcf23c5fa40d | flow:fcf23c5fa40d |
| flow | flow:3c1346ba58ae | flow:3c1346ba58ae |
| behavior_group | BSG-DATA_EXFIL-01d6c334761e | BSG-DATA_EXFIL-01d6c334761e |
| protocol_event | pe:syn:SESSION-667e285659eab6d1 | pe:syn:SESSION-667e285659eab |
| session | SESSION-ded51163dadde3d8 | SESSION-ded51163dadde3d8 |
| protocol_event | pe:rst:SESSION-e66ddcb8584d3910 | pe:rst:SESSION-e66ddcb8584d3 |
| session | SESSION-940b51c6f0328251 | SESSION-940b51c6f0328251 |
| protocol_event | pe:rst:SESSION-c1fc784f6ad7543f | pe:rst:SESSION-c1fc784f6ad75 |
| protocol_event | pe:rst:SESSION-5ea5580aef61d4b1 | pe:rst:SESSION-5ea5580aef61d |
| flow | flow:555d652bb6b5 | flow:555d652bb6b5 |
| flow | flow:05b100b5da8a | flow:05b100b5da8a |
| session | SESSION-a47134328c29a7ec | SESSION-a47134328c29a7ec |
| protocol_event | pe:syn:SESSION-dec2cc51b7fa8da3 | pe:syn:SESSION-dec2cc51b7fa8 |
| session | SESSION-990e6184fed94bbc | SESSION-990e6184fed94bbc |
| session | SESSION-277778e0ebc6b97f | SESSION-277778e0ebc6b97f |
| session | SESSION-32f1f73af1e06a94 | SESSION-32f1f73af1e06a94 |
| port_hub | 18561 | port:tcp:18561 |
| protocol_event | pe:syn:SESSION-59b4ca4a2d980591 | pe:syn:SESSION-59b4ca4a2d980 |
| port_hub | 9200 | port:tcp:9200 |
| session | SESSION-5ea5580aef61d4b1 | SESSION-5ea5580aef61d4b1 |
| session | SESSION-cf0613d8c2f24c32 | SESSION-cf0613d8c2f24c32 |
| protocol_event | pe:tls:SESSION-9e36b7b40f4c041b | pe:tls:SESSION-9e36b7b40f4c0 |
| host | 172.18.0.3 | host:172.18.0.3 |
| flow | flow:d474446d20d1 | flow:d474446d20d1 |
| flow | flow:225350b3d293 | flow:225350b3d293 |
| protocol_event | pe:syn:SESSION-011091c2af49e93e | pe:syn:SESSION-011091c2af49e |
| flow | flow:d979532da9f8 | flow:d979532da9f8 |
| session | SESSION-0d1f351cec0f2107 | SESSION-0d1f351cec0f2107 |
| flow | flow:41f0d2ac509d | flow:41f0d2ac509d |
| session | SESSION-749afb0dad1e1d5f | SESSION-749afb0dad1e1d5f |
| flow | flow:fef99555eb13 | flow:fef99555eb13 |
| session | SESSION-f055da3307c62170 | SESSION-f055da3307c62170 |
| flow | flow:1210d13c782f | flow:1210d13c782f |
| protocol_event | pe:tls:SESSION-e7f5b0482b02a2c2 | pe:tls:SESSION-e7f5b0482b02a |
| protocol_event | pe:rst:SESSION-749afb0dad1e1d5f | pe:rst:SESSION-749afb0dad1e1 |
| flow | flow:a53d2f2696c4 | flow:a53d2f2696c4 |
| session | SESSION-4630f7f752411827 | SESSION-4630f7f752411827 |
| flow | flow:8f96895f280f | flow:8f96895f280f |
| session | SESSION-7dd402a071067959 | SESSION-7dd402a071067959 |
| session | SESSION-14a0eb6f1896314a | SESSION-14a0eb6f1896314a |
| protocol_event | pe:syn:SESSION-e91c7b3d95a2a341 | pe:syn:SESSION-e91c7b3d95a2a |
| session | SESSION-c97958f2086a2a04 | SESSION-c97958f2086a2a04 |
| protocol_event | pe:syn:SESSION-244a90a5680d5b19 | pe:syn:SESSION-244a90a5680d5 |
| flow | flow:de693b8084f7 | flow:de693b8084f7 |
| session | SESSION-dfdeb9806e5d57aa | SESSION-dfdeb9806e5d57aa |
| protocol_event | pe:syn:SESSION-0e80e7ee96bff89e | pe:syn:SESSION-0e80e7ee96bff |
| session | SESSION-23e1e7d6e6bce960 | SESSION-23e1e7d6e6bce960 |
| flow | flow:46c00e4cd6d5 | flow:46c00e4cd6d5 |
| session | SESSION-0e80e7ee96bff89e | SESSION-0e80e7ee96bff89e |
| session | SESSION-b2a96b6bce11d947 | SESSION-b2a96b6bce11d947 |
| session | SESSION-d2eae1f56fe97771 | SESSION-d2eae1f56fe97771 |
| protocol_event | pe:syn:SESSION-c1686f89d9a19f19 | pe:syn:SESSION-c1686f89d9a19 |
| flow | flow:3555ecbb0c64 | flow:3555ecbb0c64 |
| protocol_event | pe:syn:SESSION-d477766246cf20f1 | pe:syn:SESSION-d477766246cf2 |
| session | SESSION-0444915f9e175b21 | SESSION-0444915f9e175b21 |
| session | SESSION-750d6db7eef625c0 | SESSION-750d6db7eef625c0 |
| flow | flow:a72cadfc1aa9 | flow:a72cadfc1aa9 |
| protocol_event | pe:syn:SESSION-277f4bd3e218bbed | pe:syn:SESSION-277f4bd3e218b |
| flow | flow:24ecd4646af3 | flow:24ecd4646af3 |
| session | SESSION-d6ff6e69cd2c280f | SESSION-d6ff6e69cd2c280f |
| session | SESSION-e7f5b0482b02a2c2 | SESSION-e7f5b0482b02a2c2 |
| flow | flow:c10bcd77afef | flow:c10bcd77afef |
| protocol_event | pe:tls:SESSION-492fa415fe812f15 | pe:tls:SESSION-492fa415fe812 |
| session | SESSION-2f4b9580a4a1affc | SESSION-2f4b9580a4a1affc |
| flow | flow:5f36207baf76 | flow:5f36207baf76 |
| session | SESSION-566f2f9c66e821a9 | SESSION-566f2f9c66e821a9 |
| protocol_event | pe:syn:SESSION-dc1073ac50d75b3b | pe:syn:SESSION-dc1073ac50d75 |
| protocol_event | pe:syn:SESSION-6a8e064b9ed3b1ba | pe:syn:SESSION-6a8e064b9ed3b |
| session | SESSION-6a8e064b9ed3b1ba | SESSION-6a8e064b9ed3b1ba |
| port_hub | 80 | port:tcp:80 |
| flow | flow:4608d170fae6 | flow:4608d170fae6 |
| session | SESSION-f3139c2f111954b1 | SESSION-f3139c2f111954b1 |
| session | SESSION-14752094e45e1b9d | SESSION-14752094e45e1b9d |
| protocol_event | pe:syn:SESSION-3e576dc0f0a4a042 | pe:syn:SESSION-3e576dc0f0a4a |
| behavior_group | BSG-DATA_EXFIL-519c5cde6966 | BSG-DATA_EXFIL-519c5cde6966 |
| flow | flow:dfcf56176c69 | flow:dfcf56176c69 |
| session | SESSION-d4a3261857bb1bce | SESSION-d4a3261857bb1bce |
| flow | flow:7604da969bd8 | flow:7604da969bd8 |
| session | SESSION-45186ed4b1e66576 | SESSION-45186ed4b1e66576 |
| protocol_event | pe:syn:SESSION-d632bcc268e1a8e7 | pe:syn:SESSION-d632bcc268e1a |
| flow | flow:46ffbe22686f | flow:46ffbe22686f |
| session | SESSION-2e061742b1675aaa | SESSION-2e061742b1675aaa |
| session | SESSION-a623632b2e50b903 | SESSION-a623632b2e50b903 |
| flow | flow:db5565d933e0 | flow:db5565d933e0 |
| port_hub | 43702 | port:tcp:43702 |
| session | SESSION-a0d57c4165f0c131 | SESSION-a0d57c4165f0c131 |
| protocol_event | pe:syn:SESSION-75ea3634dc33105f | pe:syn:SESSION-75ea3634dc331 |
| protocol_event | pe:syn:SESSION-0e178a4fe403f44f | pe:syn:SESSION-0e178a4fe403f |
| protocol_event | pe:syn:SESSION-2443586bfe5e8d85 | pe:syn:SESSION-2443586bfe5e8 |
| protocol_event | pe:rst:SESSION-c0b21b397188327f | pe:rst:SESSION-c0b21b3971883 |
| session | SESSION-9e36b7b40f4c041b | SESSION-9e36b7b40f4c041b |
| org | NetActuate, Inc | org:NetActuate, Inc |
| session | SESSION-58d7416151876432 | SESSION-58d7416151876432 |
| protocol_event | pe:syn:SESSION-41af324b19340ac8 | pe:syn:SESSION-41af324b19340 |
| host | 224.0.0.22 | host:224.0.0.22 |
| flow | flow:99423a85b18f | flow:99423a85b18f |
| flow | flow:13a1ce09df47 | flow:13a1ce09df47 |
| session | SESSION-184a45b5e113f1b1 | SESSION-184a45b5e113f1b1 |
| flow | flow:18e239b6bf4a | flow:18e239b6bf4a |
| flow | flow:21de3582b63c | flow:21de3582b63c |
| protocol_event | pe:rst:SESSION-199223c2503da80c | pe:rst:SESSION-199223c2503da |
| protocol_event | pe:tls:SESSION-e5386642f6de2d8e | pe:tls:SESSION-e5386642f6de2 |
| protocol_event | pe:syn:SESSION-a041776846043389 | pe:syn:SESSION-a041776846043 |
| port_hub | 5432 | port:tcp:5432 |
| flow | flow:46878f8663c5 | flow:46878f8663c5 |
| protocol_event | pe:syn:SESSION-1a9bc649c73d3823 | pe:syn:SESSION-1a9bc649c73d3 |
| protocol_event | pe:rst:SESSION-184a45b5e113f1b1 | pe:rst:SESSION-184a45b5e113f |
| session | SESSION-75ea3634dc33105f | SESSION-75ea3634dc33105f |
| session | SESSION-bdd2a7fadf0cfb5a | SESSION-bdd2a7fadf0cfb5a |
| flow | flow:e75f272ed551 | flow:e75f272ed551 |
| session | SESSION-94676ce1f0762fc8 | SESSION-94676ce1f0762fc8 |
| host | 172.19.0.4 | host:172.19.0.4 |
| flow | flow:cbe4878a027a | flow:cbe4878a027a |
| port_hub | 5001 | port:tcp:5001 |
| protocol_event | pe:syn:SESSION-492fa415fe812f15 | pe:syn:SESSION-492fa415fe812 |
| session | SESSION-fe6c2a163855dc38 | SESSION-fe6c2a163855dc38 |
| session | SESSION-a63ab815bc15312b | SESSION-a63ab815bc15312b |
| flow | flow:5f0e1a54e6d1 | flow:5f0e1a54e6d1 |
| protocol_event | pe:rst:SESSION-509a091ea3d0404a | pe:rst:SESSION-509a091ea3d04 |
| host | 199.165.136.101 | host:199.165.136.101 |
| protocol_event | pe:syn:SESSION-21c44b7c852f5d48 | pe:syn:SESSION-21c44b7c852f5 |
| flow | flow:f3b32c7512a6 | flow:f3b32c7512a6 |
| protocol_event | pe:syn:SESSION-df4461d50dc4a9e3 | pe:syn:SESSION-df4461d50dc4a |
| flow | flow:2fa21b49f856 | flow:2fa21b49f856 |
| session | SESSION-f2b2f468777f0928 | SESSION-f2b2f468777f0928 |
| protocol_event | pe:dns:SESSION-bdd2a7fadf0cfb5a | pe:dns:SESSION-bdd2a7fadf0cf |
| protocol_event | pe:dns:SESSION-a623632b2e50b903 | pe:dns:SESSION-a623632b2e50b |
| port_hub | 64449 | port:tcp:64449 |
| session | SESSION-e9181705548ca265 | SESSION-e9181705548ca265 |
| flow | flow:667966b2d1f4 | flow:667966b2d1f4 |
| protocol_event | pe:dns:SESSION-a189b0f57a23c78d | pe:dns:SESSION-a189b0f57a23c |
| session | SESSION-effec288f6ec645b | SESSION-effec288f6ec645b |
| session | SESSION-244a90a5680d5b19 | SESSION-244a90a5680d5b19 |
| flow | flow:f158d220910f | flow:f158d220910f |
| protocol_event | pe:syn:SESSION-749afb0dad1e1d5f | pe:syn:SESSION-749afb0dad1e1 |
| behavior_group | BSG-DATA_EXFIL-e7f288856e4c | BSG-DATA_EXFIL-e7f288856e4c |
| session | SESSION-8e9a9a4d41b52d6c | SESSION-8e9a9a4d41b52d6c |
| protocol_event | pe:syn:SESSION-a47134328c29a7ec | pe:syn:SESSION-a47134328c29a |
| protocol_event | pe:dns:SESSION-cf0613d8c2f24c32 | pe:dns:SESSION-cf0613d8c2f24 |
| protocol_event | pe:syn:SESSION-d2907c492640274a | pe:syn:SESSION-d2907c4926402 |
| session | SESSION-44f040c717a9bf93 | SESSION-44f040c717a9bf93 |
| protocol_event | pe:syn:SESSION-4a6939c5d98c00ab | pe:syn:SESSION-4a6939c5d98c0 |
| flow | flow:e4d50b3097bc | flow:e4d50b3097bc |
| protocol_event | pe:syn:SESSION-927a61c825808e80 | pe:syn:SESSION-927a61c825808 |
| flow | flow:38953798770f | flow:38953798770f |
| protocol_event | pe:syn:SESSION-88cb0f0db49ee3f8 | pe:syn:SESSION-88cb0f0db49ee |
| protocol_event | pe:syn:SESSION-a63ab815bc15312b | pe:syn:SESSION-a63ab815bc153 |
| session | SESSION-af4d92b3b5686b54 | SESSION-af4d92b3b5686b54 |
| flow | flow:6f6096676911 | flow:6f6096676911 |
| flow | flow:07c9c579a34a | flow:07c9c579a34a |
| behavior_group | BSG-DATA_EXFIL-9e0631f63080 | BSG-DATA_EXFIL-9e0631f63080 |
| flow | flow:636e5a50ec6d | flow:636e5a50ec6d |
| protocol_event | pe:syn:SESSION-8ec1e101886212aa | pe:syn:SESSION-8ec1e10188621 |
| protocol_event | pe:syn:SESSION-990e6184fed94bbc | pe:syn:SESSION-990e6184fed94 |
| flow | flow:c21ba2dd6a50 | flow:c21ba2dd6a50 |
| protocol_event | pe:syn:SESSION-4073299af13f6eb1 | pe:syn:SESSION-4073299af13f6 |
| session | SESSION-9b5f30c898183bf1 | SESSION-9b5f30c898183bf1 |
| protocol_event | pe:syn:SESSION-e9181705548ca265 | pe:syn:SESSION-e9181705548ca |
| session | SESSION-d00012345b208ef2 | SESSION-d00012345b208ef2 |
| host | 192.168.1.165 | host:192.168.1.165 |
| session | SESSION-c1686f89d9a19f19 | SESSION-c1686f89d9a19f19 |
| port_hub | 8080 | port:tcp:8080 |
| session | SESSION-6146132188ddf93c | SESSION-6146132188ddf93c |
| flow | flow:f5e4bcf9ded7 | flow:f5e4bcf9ded7 |
| protocol_event | pe:syn:SESSION-75be2d5db1cd8f86 | pe:syn:SESSION-75be2d5db1cd8 |
| protocol_event | pe:syn:SESSION-94676ce1f0762fc8 | pe:syn:SESSION-94676ce1f0762 |
| host | 172.19.0.2 | host:172.19.0.2 |
| session | SESSION-011091c2af49e93e | SESSION-011091c2af49e93e |
| protocol_event | pe:syn:SESSION-981ee5447d3b231e | pe:syn:SESSION-981ee5447d3b2 |
| flow | flow:85bf0da12a46 | flow:85bf0da12a46 |
| flow | flow:9f3c40f036a8 | flow:9f3c40f036a8 |
| flow | flow:bdddfe5081dd | flow:bdddfe5081dd |
| flow | flow:fb14909c8a55 | flow:fb14909c8a55 |
| behavior_group | BSG-DATA_EXFIL-d81594dad196 | BSG-DATA_EXFIL-d81594dad196 |
| flow | flow:5d727c97a429 | flow:5d727c97a429 |
| protocol_event | pe:syn:SESSION-f2ec323775698644 | pe:syn:SESSION-f2ec323775698 |
| session | SESSION-ecd5913739d83929 | SESSION-ecd5913739d83929 |
| protocol_event | pe:syn:SESSION-3a15d20dea9f822c | pe:syn:SESSION-3a15d20dea9f8 |
| session | SESSION-e839b37af81133b6 | SESSION-e839b37af81133b6 |
| service | http | svc:http |
| protocol_event | pe:rst:SESSION-23e1e7d6e6bce960 | pe:rst:SESSION-23e1e7d6e6bce |
| session | SESSION-50f7e5069cfb33f9 | SESSION-50f7e5069cfb33f9 |
| flow | flow:9b82e514a2be | flow:9b82e514a2be |
| session | SESSION-a94a398858e3a938 | SESSION-a94a398858e3a938 |
| protocol_event | pe:syn:SESSION-d179889405ae872b | pe:syn:SESSION-d179889405ae8 |
| protocol_event | pe:syn:SESSION-e5386642f6de2d8e | pe:syn:SESSION-e5386642f6de2 |
| protocol_event | pe:syn:SESSION-940b51c6f0328251 | pe:syn:SESSION-940b51c6f0328 |
| protocol_event | pe:syn:SESSION-14752094e45e1b9d | pe:syn:SESSION-14752094e45e1 |
| protocol_event | pe:syn:SESSION-2e061742b1675aaa | pe:syn:SESSION-2e061742b1675 |
| protocol_event | pe:dns:SESSION-d00012345b208ef2 | pe:dns:SESSION-d00012345b208 |
| port_hub | 53924 | port:tcp:53924 |
| session | SESSION-28bfb3e4b679954c | SESSION-28bfb3e4b679954c |
| session | SESSION-ac096357be763358 | SESSION-ac096357be763358 |
| session | SESSION-c8b0c60227867fbf | SESSION-c8b0c60227867fbf |
| session | SESSION-5d3fbc576ce33787 | SESSION-5d3fbc576ce33787 |
| port_hub | 443 | port:tcp:443 |
| protocol_event | pe:syn:SESSION-a94a398858e3a938 | pe:syn:SESSION-a94a398858e3a |
| tls_sni | tls_sni:chatgpt.com | tls_sni:chatgpt.com |
| flow | flow:1c2177d1cc9e | flow:1c2177d1cc9e |
| session | SESSION-bdbff71b9738f136 | SESSION-bdbff71b9738f136 |
| session | SESSION-f2ec323775698644 | SESSION-f2ec323775698644 |
| protocol_event | pe:syn:SESSION-80112cd9041913ff | pe:syn:SESSION-80112cd904191 |
| flow | flow:b5aa0b7e2a62 | flow:b5aa0b7e2a62 |
| flow | flow:892de9cc0c20 | flow:892de9cc0c20 |
| flow | flow:a4751f258f2d | flow:a4751f258f2d |
| protocol_event | pe:syn:SESSION-5fba0156cbdcef6a | pe:syn:SESSION-5fba0156cbdce |
| session | SESSION-db16a6acc2ffa01a | SESSION-db16a6acc2ffa01a |
| flow | flow:0ad5527089d5 | flow:0ad5527089d5 |
| protocol_event | pe:syn:SESSION-4d3f1d43883a9ff8 | pe:syn:SESSION-4d3f1d43883a9 |
| host | 140.82.112.22 | host:140.82.112.22 |
| protocol_event | pe:syn:SESSION-0d1f351cec0f2107 | pe:syn:SESSION-0d1f351cec0f2 |
| protocol_event | pe:syn:SESSION-e7f5b0482b02a2c2 | pe:syn:SESSION-e7f5b0482b02a |
| session | SESSION-9bb086254b883840 | SESSION-9bb086254b883840 |
| protocol_event | pe:syn:SESSION-cbe987946fcf62e6 | pe:syn:SESSION-cbe987946fcf6 |
| session | SESSION-0c892504383e1ab6 | SESSION-0c892504383e1ab6 |
| host | 100.79.241.36 | host:100.79.241.36 |
| session | SESSION-84e3f9c68c52ff85 | SESSION-84e3f9c68c52ff85 |
| protocol_event | pe:syn:SESSION-a0d57c4165f0c131 | pe:syn:SESSION-a0d57c4165f0c |
| protocol_event | pe:syn:SESSION-ac096357be763358 | pe:syn:SESSION-ac096357be763 |
| session | SESSION-87e1e4a9feb70e76 | SESSION-87e1e4a9feb70e76 |
| service | mysql | svc:mysql |
| flow | flow:d37b9b20e141 | flow:d37b9b20e141 |
| session | SESSION-b9d428e36cb4ed21 | SESSION-b9d428e36cb4ed21 |
| flow | flow:5894cb4983f2 | flow:5894cb4983f2 |
| protocol_event | pe:syn:SESSION-fa07559c364104a9 | pe:syn:SESSION-fa07559c36410 |
| host | 172.18.0.1 | host:172.18.0.1 |
| session | SESSION-59b4ca4a2d980591 | SESSION-59b4ca4a2d980591 |
| geo_point | geo_43.63190_-79.37160 | geo_43.63190_-79.37160 |
| flow | flow:1ab8aeec54c3 | flow:1ab8aeec54c3 |
| flow | flow:140788ba2a4a | flow:140788ba2a4a |
| flow | flow:c4a365368eec | flow:c4a365368eec |
| session | SESSION-a041776846043389 | SESSION-a041776846043389 |
| protocol_event | pe:syn:SESSION-bdbff71b9738f136 | pe:syn:SESSION-bdbff71b9738f |
| session | SESSION-5e5900c4e76e2265 | SESSION-5e5900c4e76e2265 |
| protocol_event | pe:syn:SESSION-566f2f9c66e821a9 | pe:syn:SESSION-566f2f9c66e82 |
| session | SESSION-3c46a3ae1cdb9298 | SESSION-3c46a3ae1cdb9298 |
| flow | flow:9bef0258ca83 | flow:9bef0258ca83 |
| dns_name | dns:chatgpt.com | dns:chatgpt.com |
| session | SESSION-3f0ef7f428c88827 | SESSION-3f0ef7f428c88827 |
| flow | flow:c19e65a4f85d | flow:c19e65a4f85d |
| flow | flow:4f77cf2630d3 | flow:4f77cf2630d3 |
| session | SESSION-f2807176b717b104 | SESSION-f2807176b717b104 |
| flow | flow:81404d80276b | flow:81404d80276b |
| flow | flow:30de99e1d052 | flow:30de99e1d052 |
| session | SESSION-3cff2087dd31b50e | SESSION-3cff2087dd31b50e |
| protocol_event | pe:syn:SESSION-837c8f23b8a11f0a | pe:syn:SESSION-837c8f23b8a11 |
| protocol_event | pe:syn:SESSION-5a7d4c69e0c5166f | pe:syn:SESSION-5a7d4c69e0c51 |
| flow | flow:35574545b174 | flow:35574545b174 |
| port_hub | 43706 | port:tcp:43706 |
| protocol_event | pe:syn:SESSION-9bb086254b883840 | pe:syn:SESSION-9bb086254b883 |
| session | SESSION-1a9bc649c73d3823 | SESSION-1a9bc649c73d3823 |
| port_hub | 46602 | port:tcp:46602 |
| flow | flow:074a4aa2327c | flow:074a4aa2327c |
| flow | flow:ce9a161356b8 | flow:ce9a161356b8 |
| protocol_event | pe:syn:SESSION-aa0c67f00e6b14ec | pe:syn:SESSION-aa0c67f00e6b1 |
| protocol_event | pe:rst:SESSION-aa0c67f00e6b14ec | pe:rst:SESSION-aa0c67f00e6b1 |
| behavior_group | BSG-PORT_SCAN-1cabee609aa8 | BSG-PORT_SCAN-1cabee609aa8 |
| host | 192.200.0.105 | host:192.200.0.105 |
| protocol_event | pe:syn:SESSION-b9d428e36cb4ed21 | pe:syn:SESSION-b9d428e36cb4e |
| dns_name | dns:api.individual.githubcopilot.com | dns:api.individual.githubcop |
| flow | flow:cb68572bfaf1 | flow:cb68572bfaf1 |
| session | SESSION-d632bcc268e1a8e7 | SESSION-d632bcc268e1a8e7 |
| flow | flow:03c3304f1052 | flow:03c3304f1052 |
| service | https | svc:https |
| host | 209.177.156.94 | host:209.177.156.94 |
| flow | flow:c2cf1f0d0e58 | flow:c2cf1f0d0e58 |
| flow | flow:b1cf9538df38 | flow:b1cf9538df38 |
| flow | flow:c6a2ce0cfd79 | flow:c6a2ce0cfd79 |
| http_host | http_host:neurosphere-2.tail52f848.ts.net | http_host:neurosphere-2.tail |
| flow | flow:5d44821e36cb | flow:5d44821e36cb |
| session | SESSION-e13fd7d198093746 | SESSION-e13fd7d198093746 |
| session | SESSION-f1084471ac1c8494 | SESSION-f1084471ac1c8494 |
| session | SESSION-75be2d5db1cd8f86 | SESSION-75be2d5db1cd8f86 |
| protocol_event | pe:syn:SESSION-8e9a9a4d41b52d6c | pe:syn:SESSION-8e9a9a4d41b52 |
| protocol_event | pe:syn:SESSION-3cff2087dd31b50e | pe:syn:SESSION-3cff2087dd31b |
| session | SESSION-feb55551c2670490 | SESSION-feb55551c2670490 |
| flow | flow:5c6ad158de45 | flow:5c6ad158de45 |
| protocol_event | pe:tls:SESSION-4630f7f752411827 | pe:tls:SESSION-4630f7f752411 |
| behavior_group | BSG-BEACON-d3bb221a98cc | BSG-BEACON-d3bb221a98cc |
| flow | flow:d9f0f9995423 | flow:d9f0f9995423 |
| flow | flow:6b5754955308 | flow:6b5754955308 |
| protocol_event | pe:rst:SESSION-b8aaaeead9846ee4 | pe:rst:SESSION-b8aaaeead9846 |
| protocol_event | pe:syn:SESSION-d6ff6e69cd2c280f | pe:syn:SESSION-d6ff6e69cd2c2 |
| port_hub | 62747 | port:tcp:62747 |
| protocol_event | pe:rst:SESSION-e2e42d020fcf6d9e | pe:rst:SESSION-e2e42d020fcf6 |
| session | SESSION-4f67a12166716c27 | SESSION-4f67a12166716c27 |
| org | GitHub, Inc. | org:GitHub, Inc. |
| flow | flow:ec2e0a1ac2e8 | flow:ec2e0a1ac2e8 |
| protocol_event | pe:syn:SESSION-273cd57b7353458c | pe:syn:SESSION-273cd57b73534 |
| flow | flow:d79e2f7db057 | flow:d79e2f7db057 |
| session | SESSION-4d3f1d43883a9ff8 | SESSION-4d3f1d43883a9ff8 |
| flow | flow:7a2a603567b2 | flow:7a2a603567b2 |
| service | postgres | svc:postgres |
| session | SESSION-f57a2b61ffd77e70 | SESSION-f57a2b61ffd77e70 |
| session | SESSION-3e576dc0f0a4a042 | SESSION-3e576dc0f0a4a042 |
| session | SESSION-492fa415fe812f15 | SESSION-492fa415fe812f15 |
| flow | flow:5ce5c2f40363 | flow:5ce5c2f40363 |
| session | SESSION-4073299af13f6eb1 | SESSION-4073299af13f6eb1 |
| flow | flow:8afba61beb97 | flow:8afba61beb97 |
| flow | flow:759e5d156181 | flow:759e5d156181 |
| session | SESSION-4a6939c5d98c00ab | SESSION-4a6939c5d98c00ab |
| port_hub | 59861 | port:tcp:59861 |
| session | SESSION-e589e5d027c1a0b6 | SESSION-e589e5d027c1a0b6 |
| flow | flow:1a24dc9be672 | flow:1a24dc9be672 |
| flow | flow:3997fb6a944d | flow:3997fb6a944d |
| session | SESSION-e2e42d020fcf6d9e | SESSION-e2e42d020fcf6d9e |
| protocol_event | pe:tls:SESSION-dfdeb9806e5d57aa | pe:tls:SESSION-dfdeb9806e5d5 |
| host | 192.168.1.185 | host:192.168.1.185 |
| flow | flow:d4f11f511722 | flow:d4f11f511722 |
| protocol_event | pe:syn:SESSION-47b317e81372877c | pe:syn:SESSION-47b317e813728 |
| protocol_event | pe:syn:SESSION-509a091ea3d0404a | pe:syn:SESSION-509a091ea3d04 |
| flow | flow:015001f8dd97 | flow:015001f8dd97 |
| protocol_event | pe:rst:SESSION-3cff2087dd31b50e | pe:rst:SESSION-3cff2087dd31b |
| flow | flow:0ad67992f4b2 | flow:0ad67992f4b2 |
| session | SESSION-41af324b19340ac8 | SESSION-41af324b19340ac8 |
| flow | flow:49c9bc562a9b | flow:49c9bc562a9b |
| session | SESSION-199223c2503da80c | SESSION-199223c2503da80c |
| session | SESSION-068dad59cf1e736c | SESSION-068dad59cf1e736c |
| flow | flow:20513f6dd4e5 | flow:20513f6dd4e5 |
| protocol_event | pe:rst:SESSION-0d1f351cec0f2107 | pe:rst:SESSION-0d1f351cec0f2 |
| flow | flow:aedd679b297d | flow:aedd679b297d |
| session | SESSION-2443586bfe5e8d85 | SESSION-2443586bfe5e8d85 |
| session | SESSION-e66ddcb8584d3910 | SESSION-e66ddcb8584d3910 |
| protocol_event | pe:dns:SESSION-eade9b324c3f2d97 | pe:dns:SESSION-eade9b324c3f2 |
| flow | flow:f0e8dbb2758f | flow:f0e8dbb2758f |
| flow | flow:f64aa9e4e2d2 | flow:f64aa9e4e2d2 |
| protocol_event | pe:syn:SESSION-b6f423fe62c07433 | pe:syn:SESSION-b6f423fe62c07 |
| protocol_event | pe:syn:SESSION-aa99cce81b7c8c65 | pe:syn:SESSION-aa99cce81b7c8 |
| protocol_event | pe:syn:SESSION-f2807176b717b104 | pe:syn:SESSION-f2807176b717b |
| flow | flow:6e7bd7231e78 | flow:6e7bd7231e78 |
| session | SESSION-1532f0a81e6464f4 | SESSION-1532f0a81e6464f4 |
| session | SESSION-df3a1bb7bb52ead6 | SESSION-df3a1bb7bb52ead6 |
| protocol_event | pe:syn:SESSION-8d137995a1d20bf6 | pe:syn:SESSION-8d137995a1d20 |
| flow | flow:437f27218a12 | flow:437f27218a12 |
| session | SESSION-c0b21b397188327f | SESSION-c0b21b397188327f |
| pcap_artifact | PCAP:pcapng_neurosphere_20260528_153001:5500f3564330 | PCAP:pcapng_neurosphere_2026 |
| session | SESSION-dc1073ac50d75b3b | SESSION-dc1073ac50d75b3b |
| session | SESSION-80112cd9041913ff | SESSION-80112cd9041913ff |
| flow | flow:46dcd040989f | flow:46dcd040989f |
| protocol_event | pe:rst:SESSION-7777479b5176757e | pe:rst:SESSION-7777479b51767 |
| session | SESSION-667e285659eab6d1 | SESSION-667e285659eab6d1 |
| flow | flow:f896ae6f3980 | flow:f896ae6f3980 |
| session | SESSION-d2907c492640274a | SESSION-d2907c492640274a |
| protocol_event | pe:syn:SESSION-6146132188ddf93c | pe:syn:SESSION-6146132188ddf |
| flow | flow:6e6e6529818a | flow:6e6e6529818a |
| flow | flow:558be580ae09 | flow:558be580ae09 |
| protocol_event | pe:rst:SESSION-d477766246cf20f1 | pe:rst:SESSION-d477766246cf2 |
| protocol_event | pe:syn:SESSION-f0ba11b9cd11605f | pe:syn:SESSION-f0ba11b9cd116 |
| protocol_event | pe:syn:SESSION-c0b21b397188327f | pe:syn:SESSION-c0b21b3971883 |
| flow | flow:300bab707f3b | flow:300bab707f3b |
| host | 172.19.0.3 | host:172.19.0.3 |
| session | SESSION-837c8f23b8a11f0a | SESSION-837c8f23b8a11f0a |
| flow | flow:b5adba690a07 | flow:b5adba690a07 |
| session | SESSION-0e178a4fe403f44f | SESSION-0e178a4fe403f44f |
| flow | flow:197c1938daa6 | flow:197c1938daa6 |
| protocol_event | pe:syn:SESSION-3be06d33bb623daa | pe:syn:SESSION-3be06d33bb623 |
| protocol_event | pe:syn:SESSION-e13fd7d198093746 | pe:syn:SESSION-e13fd7d198093 |
| port_hub | 44718 | port:tcp:44718 |
| behavior_group | BSG-DATA_EXFIL-a88fc270bff4 | BSG-DATA_EXFIL-a88fc270bff4 |
| protocol_event | pe:syn:SESSION-784867f162cdac65 | pe:syn:SESSION-784867f162cda |
| asn | asn:36236 | asn:36236 |
| session | SESSION-e0cd994b6ff4b517 | SESSION-e0cd994b6ff4b517 |
| flow | flow:d81edc4a502c | flow:d81edc4a502c |
| session | SESSION-8266fc4f0c69a273 | SESSION-8266fc4f0c69a273 |
| flow | flow:3c62b09703b9 | flow:3c62b09703b9 |
| protocol_event | pe:syn:SESSION-58d7416151876432 | pe:syn:SESSION-58d7416151876 |
| protocol_event | pe:syn:SESSION-44f040c717a9bf93 | pe:syn:SESSION-44f040c717a9b |
| port_hub | 61412 | port:tcp:61412 |
| flow | flow:2a18aa40ab8e | flow:2a18aa40ab8e |
| port_hub | 53886 | port:tcp:53886 |
| flow | flow:80cfd7757bd5 | flow:80cfd7757bd5 |
| session | SESSION-b6f423fe62c07433 | SESSION-b6f423fe62c07433 |
| protocol_event | pe:syn:SESSION-e0850aee2c012568 | pe:syn:SESSION-e0850aee2c012 |
| flow | flow:ebb01df8f6ce | flow:ebb01df8f6ce |
| session | SESSION-927a61c825808e80 | SESSION-927a61c825808e80 |
| flow | flow:b230f8102bec | flow:b230f8102bec |
| flow | flow:b84ec75d0e28 | flow:b84ec75d0e28 |
| flow | flow:cf0b462ed092 | flow:cf0b462ed092 |
| protocol_event | pe:rst:SESSION-87e1e4a9feb70e76 | pe:rst:SESSION-87e1e4a9feb70 |
| session | SESSION-a41a7a8f59802490 | SESSION-a41a7a8f59802490 |
| protocol_event | pe:syn:SESSION-db16a6acc2ffa01a | pe:syn:SESSION-db16a6acc2ffa |
| session | SESSION-707f3d5cd8febf7c | SESSION-707f3d5cd8febf7c |
| flow | flow:ec06c3bd9cbf | flow:ec06c3bd9cbf |
| session | SESSION-dd725f94abd254e2 | SESSION-dd725f94abd254e2 |
| port_hub | 53 | port:udp:53 |
| protocol_event | pe:syn:SESSION-df3a1bb7bb52ead6 | pe:syn:SESSION-df3a1bb7bb52e |
| protocol_event | pe:syn:SESSION-f57a2b61ffd77e70 | pe:syn:SESSION-f57a2b61ffd77 |
| flow | flow:ff1b3220cb76 | flow:ff1b3220cb76 |
| flow | flow:c9ab213267d8 | flow:c9ab213267d8 |
| protocol_event | pe:syn:SESSION-e10fa25545d53b19 | pe:syn:SESSION-e10fa25545d53 |
| flow | flow:695c4028e98f | flow:695c4028e98f |
| session | SESSION-5a7d4c69e0c5166f | SESSION-5a7d4c69e0c5166f |
| flow | flow:d334691a6390 | flow:d334691a6390 |
| flow | flow:7802d953df03 | flow:7802d953df03 |
| behavior_group | BSG-BEACON-fcd3aa7190ae | BSG-BEACON-fcd3aa7190ae |
| host | 172.18.0.2 | host:172.18.0.2 |
| session | SESSION-7777479b5176757e | SESSION-7777479b5176757e |
| host | 104.18.32.47 | host:104.18.32.47 |
| session | SESSION-784867f162cdac65 | SESSION-784867f162cdac65 |
| flow | flow:92bf5d7fa780 | flow:92bf5d7fa780 |
| protocol_event | pe:syn:SESSION-e56034d531876f8e | pe:syn:SESSION-e56034d531876 |
| asn | asn:36459 | asn:36459 |
| flow | flow:8a8a928a7285 | flow:8a8a928a7285 |
| flow | flow:7147cc90c8a0 | flow:7147cc90c8a0 |
| session | SESSION-981ee5447d3b231e | SESSION-981ee5447d3b231e |
| port_hub | 44833 | port:tcp:44833 |
| asn | asn:16509 | asn:16509 |
| asn | asn:14618 | asn:14618 |
| session | SESSION-277f4bd3e218bbed | SESSION-277f4bd3e218bbed |
| flow | flow:4694dd225d88 | flow:4694dd225d88 |
| protocol_event | pe:syn:SESSION-5e5900c4e76e2265 | pe:syn:SESSION-5e5900c4e76e2 |
| geo_point | geo_37.75100_-97.82200 | geo_37.75100_-97.82200 |
| tls_sni | tls_sni:api.individual.githubcopilot.com | tls_sni:api.individual.githu |
| protocol_event | pe:syn:SESSION-3c46a3ae1cdb9298 | pe:syn:SESSION-3c46a3ae1cdb9 |
| flow | flow:ec34ee35ec03 | flow:ec34ee35ec03 |
| protocol_event | pe:syn:SESSION-a4fad28b257d25e0 | pe:syn:SESSION-a4fad28b257d2 |
| flow | flow:26fa4690abd9 | flow:26fa4690abd9 |
| session | SESSION-907d871bde93803f | SESSION-907d871bde93803f |
| flow | flow:56eb219b4e0f | flow:56eb219b4e0f |
| session | SESSION-509a091ea3d0404a | SESSION-509a091ea3d0404a |
| session | SESSION-c26fa3267a66e449 | SESSION-c26fa3267a66e449 |
| protocol_event | pe:syn:SESSION-5b564b5673a8375f | pe:syn:SESSION-5b564b5673a83 |
| session | SESSION-aa0c67f00e6b14ec | SESSION-aa0c67f00e6b14ec |
| protocol_event | pe:syn:SESSION-068dad59cf1e736c | pe:syn:SESSION-068dad59cf1e7 |
| session | SESSION-f0cac35db2fab18a | SESSION-f0cac35db2fab18a |
| geo_point | geo_32.77970_-96.80220 | geo_32.77970_-96.80220 |
| Kind | Src | Dst | |
|---|---|---|---|
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_QUERIED_DNS | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| ASN_IN_ORG | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| HOST_IN_ASN | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_QUERIED_DNS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| PORT_IMPLIED_SERVICE | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| PORT_IMPLIED_SERVICE | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| HOST_GEO_ESTIMATE | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TLS_SNI | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| HOST_GEO_ESTIMATE | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_QUERIED_DNS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| flow_observed | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| HOST_IN_ASN | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| FLOW_FROM_HOST | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_QUERIED_DNS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| HOST_GEO_ESTIMATE | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| PORT_IMPLIED_SERVICE | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_TO_HOST | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| ASN_IN_ORG | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| ASN_IN_ORG | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| PORT_IMPLIED_SERVICE | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| HOST_IN_ASN | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| FLOW_HTTP_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| ASN_IN_ORG | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| FLOW_FROM_HOST | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_FROM_HOST | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_QUERIED_DNS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| FLOW_QUERIED_DNS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_QUERIED_DNS | β | ||
| FLOW_QUERIED_DNS | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TO_HOST | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TO_HOST | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| HOST_IN_ASN | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_HTTP_HOST | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TLS_SNI | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TLS_SNI | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_TO_HOST | β | ||
| flow_observed | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_QUERIED_DNS | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_DST_PORT | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| HOST_GEO_ESTIMATE | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| PORT_IMPLIED_SERVICE | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| PORT_IMPLIED_SERVICE | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β |