Nodes (120)
Edges (253)
| Kind | Label | ID |
|---|---|---|
| geo_point | geo_49.44230_11.01910 | geo_49.44230_11.01910 |
| asn | asn:714 | asn:714 |
| flow | flow:0d727e2708b4 | flow:0d727e2708b4 |
| host | 199.16.157.183 | host:199.16.157.183 |
| protocol_event | pe:tls:SESSION-c365d629ce285be9 | pe:tls:SESSION-c365d629ce285 |
| asn | asn:197540 | asn:197540 |
| host | 46.38.236.138 | host:46.38.236.138 |
| service | https | svc:https |
| host | 97.139.12.85 | host:97.139.12.85 |
| port_hub | 443 | port:tcp:443 |
| session | SESSION-32c3b80c2cc69cbc | SESSION-32c3b80c2cc69cbc |
| behavior_group | BSG-DATA_EXFIL-c45ebda152e5 | BSG-DATA_EXFIL-c45ebda152e5 |
| flow | flow:da7065edff23 | flow:da7065edff23 |
| protocol_event | pe:tls:SESSION-df0521ee237a9620 | pe:tls:SESSION-df0521ee237a9 |
| behavior_group | BSG-DATA_EXFIL-012d574517f4 | BSG-DATA_EXFIL-012d574517f4 |
| session | SESSION-bd11a50065a6cb7c | SESSION-bd11a50065a6cb7c |
| flow | flow:c37aaecdcc9a | flow:c37aaecdcc9a |
| protocol_event | pe:dns:SESSION-32c3b80c2cc69cbc | pe:dns:SESSION-32c3b80c2cc69 |
| flow | flow:67799a4b0206 | flow:67799a4b0206 |
| asn | asn:13414 | asn:13414 |
| protocol_event | pe:tls:SESSION-6b6584907add35ca | pe:tls:SESSION-6b6584907add3 |
| session | SESSION-2b16ad2cc059d584 | SESSION-2b16ad2cc059d584 |
| behavior_group | BSG-DATA_EXFIL-6dd8484f3944 | BSG-DATA_EXFIL-6dd8484f3944 |
| protocol_event | pe:syn:SESSION-01a793e8041caae3 | pe:syn:SESSION-01a793e8041ca |
| behavior_group | BSG-DATA_EXFIL-0b1600805959 | BSG-DATA_EXFIL-0b1600805959 |
| protocol_event | pe:syn:SESSION-2b16ad2cc059d584 | pe:syn:SESSION-2b16ad2cc059d |
| behavior_group | BSG-DATA_EXFIL-e6f479c60e03 | BSG-DATA_EXFIL-e6f479c60e03 |
| protocol_event | pe:syn:SESSION-6b6584907add35ca | pe:syn:SESSION-6b6584907add3 |
| org | Microsoft Corporation | org:Microsoft Corporation |
| protocol_event | pe:syn:SESSION-7b48e5e7105113e9 | pe:syn:SESSION-7b48e5e710511 |
| session | SESSION-6b6584907add35ca | SESSION-6b6584907add35ca |
| protocol_event | pe:tls:SESSION-43328f9b50a5d423 | pe:tls:SESSION-43328f9b50a5d |
| tls_sni | tls_sni:172-234-197-23.ip.linodeusercontent.com | tls_sni:172-234-197-23.ip.li |
| host | 144.76.23.47 | host:144.76.23.47 |
| flow | flow:a46be0b84889 | flow:a46be0b84889 |
| flow | flow:93cba7dfff64 | flow:93cba7dfff64 |
| protocol_event | pe:dns:SESSION-f952d347444430eb | pe:dns:SESSION-f952d34744443 |
| host | 172.232.0.17 | host:172.232.0.17 |
| geo_point | geo_29.81190_-95.52070 | geo_29.81190_-95.52070 |
| flow | flow:99a9f8b7c5b3 | flow:99a9f8b7c5b3 |
| protocol_event | pe:dns:SESSION-e15010a8a1e57ef1 | pe:dns:SESSION-e15010a8a1e57 |
| protocol_event | pe:tls:SESSION-01a793e8041caae3 | pe:tls:SESSION-01a793e8041ca |
| flow | flow:66bb27cf4c04 | flow:66bb27cf4c04 |
| protocol_event | pe:tls:SESSION-bd11a50065a6cb7c | pe:tls:SESSION-bd11a50065a6c |
| flow | flow:991e601541a1 | flow:991e601541a1 |
| protocol_event | pe:rst:SESSION-43328f9b50a5d423 | pe:rst:SESSION-43328f9b50a5d |
| protocol_event | pe:tls:SESSION-f8e62b0ad557062a | pe:tls:SESSION-f8e62b0ad5570 |
| behavior_group | BSG-DATA_EXFIL-58becbf84c75 | BSG-DATA_EXFIL-58becbf84c75 |
| flow | flow:2c6c48655616 | flow:2c6c48655616 |
| host | 17.22.237.22 | host:17.22.237.22 |
| port_hub | 60136 | port:tcp:60136 |
| host | 199.16.157.182 | host:199.16.157.182 |
| geo_point | geo_29.42270_-98.49270 | geo_29.42270_-98.49270 |
| asn | asn:6167 | asn:6167 |
| protocol_event | pe:tls:SESSION-5ae5c17cec58f583 | pe:tls:SESSION-5ae5c17cec58f |
| flow | flow:6ac8bc7ce374 | flow:6ac8bc7ce374 |
| org | Akamai Connected Cloud | org:Akamai Connected Cloud |
| org | Twitter Inc. | org:Twitter Inc. |
| org | Tencent Building, Kejizhongyi Avenue | org:Tencent Building, Kejizh |
| geo_point | geo_33.76970_-84.37540 | geo_33.76970_-84.37540 |
| session | SESSION-f952d347444430eb | SESSION-f952d347444430eb |
| protocol_event | pe:tls:SESSION-8a981e11d869c723 | pe:tls:SESSION-8a981e11d869c |
| session | SESSION-c365d629ce285be9 | SESSION-c365d629ce285be9 |
| pcap_artifact | PCAP:DevOpsPage_20260423_1021pmCST:40cef681a237 | PCAP:DevOpsPage_20260423_102 |
| asn | asn:24940 | asn:24940 |
| protocol_event | pe:tls:SESSION-c52a62f7c65f2e1a | pe:tls:SESSION-c52a62f7c65f2 |
| protocol_event | pe:tls:SESSION-e9f4a4a9c8d0d99f | pe:tls:SESSION-e9f4a4a9c8d0d |
| session | SESSION-7b48e5e7105113e9 | SESSION-7b48e5e7105113e9 |
| session | SESSION-f8e62b0ad557062a | SESSION-f8e62b0ad557062a |
| host | 43.135.145.73 | host:43.135.145.73 |
| flow | flow:958f77dbf2ff | flow:958f77dbf2ff |
| session | SESSION-c52a62f7c65f2e1a | SESSION-c52a62f7c65f2e1a |
| protocol_event | pe:rst:SESSION-bd11a50065a6cb7c | pe:rst:SESSION-bd11a50065a6c |
| session | SESSION-124f188fc662f45b | SESSION-124f188fc662f45b |
| protocol_event | pe:tls:SESSION-124f188fc662f45b | pe:tls:SESSION-124f188fc662f |
| session | SESSION-01a793e8041caae3 | SESSION-01a793e8041caae3 |
| session | SESSION-7f4ca9b0d8673927 | SESSION-7f4ca9b0d8673927 |
| protocol_event | pe:tls:SESSION-7b48e5e7105113e9 | pe:tls:SESSION-7b48e5e710511 |
| session | SESSION-43328f9b50a5d423 | SESSION-43328f9b50a5d423 |
| session | SESSION-e9f4a4a9c8d0d99f | SESSION-e9f4a4a9c8d0d99f |
| protocol_event | pe:syn:SESSION-c52a62f7c65f2e1a | pe:syn:SESSION-c52a62f7c65f2 |
| asn | asn:132203 | asn:132203 |
| session | SESSION-e15010a8a1e57ef1 | SESSION-e15010a8a1e57ef1 |
| port_hub | 53 | port:udp:53 |
| session | SESSION-5ae5c17cec58f583 | SESSION-5ae5c17cec58f583 |
| geo_point | geo_37.75100_-97.82200 | geo_37.75100_-97.82200 |
| session | SESSION-df0521ee237a9620 | SESSION-df0521ee237a9620 |
| host | 40.119.32.47 | host:40.119.32.47 |
| behavior_group | BSG-DATA_EXFIL-ba0a9ef14e5d | BSG-DATA_EXFIL-ba0a9ef14e5d |
| protocol_event | pe:syn:SESSION-e9f4a4a9c8d0d99f | pe:syn:SESSION-e9f4a4a9c8d0d |
| flow | flow:4cb79ca168a0 | flow:4cb79ca168a0 |
| flow | flow:6f0c0a999555 | flow:6f0c0a999555 |
| protocol_event | pe:rst:SESSION-01a793e8041caae3 | pe:rst:SESSION-01a793e8041ca |
| geo_point | geo_50.47770_12.36490 | geo_50.47770_12.36490 |
| org | Hetzner Online GmbH | org:Hetzner Online GmbH |
| geo_point | geo_37.35300_-121.95440 | geo_37.35300_-121.95440 |
| flow | flow:4eaa609c2624 | flow:4eaa609c2624 |
| dns_name | dns:172-234-197-23.ip.linodeusercontent.com | dns:172-234-197-23.ip.linode |
| org | Verizon Business | org:Verizon Business |
| host | 172.234.197.23 | host:172.234.197.23 |
| asn | asn:63949 | asn:63949 |
| protocol_event | pe:tls:SESSION-2b16ad2cc059d584 | pe:tls:SESSION-2b16ad2cc059d |
| protocol_event | pe:syn:SESSION-124f188fc662f45b | pe:syn:SESSION-124f188fc662f |
| protocol_event | pe:syn:SESSION-bd11a50065a6cb7c | pe:syn:SESSION-bd11a50065a6c |
| protocol_event | pe:dns:SESSION-7f4ca9b0d8673927 | pe:dns:SESSION-7f4ca9b0d8673 |
| session | SESSION-1ca6064244966ba9 | SESSION-1ca6064244966ba9 |
| flow | flow:b8c49dd508ec | flow:b8c49dd508ec |
| flow | flow:10959da4f2fa | flow:10959da4f2fa |
| asn | asn:8075 | asn:8075 |
| service | dns | svc:dns |
| flow | flow:c51bf5b097ea | flow:c51bf5b097ea |
| behavior_group | BSG-DATA_EXFIL-c24d7cb3a7e4 | BSG-DATA_EXFIL-c24d7cb3a7e4 |
| host | 199.16.157.181 | host:199.16.157.181 |
| geo_point | geo_41.88350_-87.63050 | geo_41.88350_-87.63050 |
| org | Apple Inc. | org:Apple Inc. |
| org | netcup GmbH | org:netcup GmbH |
| protocol_event | pe:syn:SESSION-43328f9b50a5d423 | pe:syn:SESSION-43328f9b50a5d |
| session | SESSION-8a981e11d869c723 | SESSION-8a981e11d869c723 |
| flow | flow:28bd443b2c5e | flow:28bd443b2c5e |
| protocol_event | pe:rst:SESSION-6b6584907add35ca | pe:rst:SESSION-6b6584907add3 |
| Kind | Src | Dst | |
|---|---|---|---|
| FLOW_TO_HOST | β | ||
| HOST_GEO_ESTIMATE | β | ||
| FLOW_QUERIED_DNS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| HOST_IN_ASN | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| PORT_IMPLIED_SERVICE | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_QUERIED_DNS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| ASN_IN_ORG | β | ||
| FLOW_TO_HOST | β | ||
| ASN_IN_ORG | β | ||
| SESSION_OBSERVED_HOST | β | ||
| HOST_IN_ASN | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| HOST_GEO_ESTIMATE | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| ASN_IN_ORG | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| HOST_GEO_ESTIMATE | β | ||
| ASN_IN_ORG | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| HOST_IN_ASN | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| HOST_GEO_ESTIMATE | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_TLS_SNI | β | ||
| FLOW_TO_HOST | β | ||
| HOST_IN_ASN | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_FROM_HOST | β | ||
| flow_observed | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| flow_observed | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| HOST_GEO_ESTIMATE | β | ||
| flow_observed | β | ||
| flow_observed | β | ||
| HOST_GEO_ESTIMATE | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| ASN_IN_ORG | β | ||
| FLOW_QUERIED_DNS | β | ||
| HOST_GEO_ESTIMATE | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_DST_PORT | β | ||
| HOST_IN_ASN | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| HOST_GEO_ESTIMATE | β | ||
| FLOW_DST_PORT | β | ||
| HOST_IN_ASN | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| HOST_IN_ASN | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| ASN_IN_ORG | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_TLS_SNI | β | ||
| flow_observed | β | ||
| HOST_GEO_ESTIMATE | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_QUERIED_DNS | β | ||
| FLOW_TLS_SNI | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TLS_SNI | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_TLS_SNI | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| flow_observed | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| HOST_GEO_ESTIMATE | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_TLS_SNI | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| HOST_IN_ASN | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| HOST_IN_ASN | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| HOST_GEO_ESTIMATE | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| flow_observed | β | ||
| HOST_IN_ASN | β | ||
| FLOW_TLS_SNI | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| FLOW_DST_PORT | β | ||
| PORT_IMPLIED_SERVICE | β | ||
| FLOW_FROM_HOST | β | ||
| HOST_IN_ASN | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| ASN_IN_ORG | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| ASN_IN_ORG | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_BETWEEN_HOSTS | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| flow_observed | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| FLOW_TO_HOST | β | ||
| flow_observed | β | ||
| FLOW_TO_HOST | β | ||
| FLOW_TO_HOST | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| flow_observed | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_DERIVED_FROM_PCAP | β | ||
| SESSION_MEMBER_OF_BEHAVIOR_GROUP | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_FLOW | β | ||
| SESSION_OBSERVED_HOST | β | ||
| FLOW_FROM_HOST | β | ||
| FLOW_DST_PORT | β | ||
| SESSION_CONTAINS_EVENT | β | ||
| SESSION_OBSERVED_HOST | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β | ||
| SESSION_OBSERVED_HOST | β | ||
| flow_observed | β |